The Illusion of Detection

Many organizations opt for self-hosted Security Information and Event Management (SIEM) systems, driven by the perceived cost savings. The math appears straightforward: a lower licensing cost, a single engineer, and a console that consistently displays a green status. This financial benefit is tangible, impacting the P&L every month. However, this approach often overlooks a critical exposure hidden from financial statements. The true value proposition of a SIEM is detection, yet the console primarily validates ingestion. These are distinct metrics, and during a genuine security incident, the illusion of healthy ingestion can mask a critical failure in actual detection.

A recent, albeit personal, measurement highlights this deficiency. Using a default Wazuh build with stock rules, without any tuning, 24 MITRE ATT&CK techniques were replayed against the system on September 1st, 2026. The results were stark: only three of these techniques triggered an alert. Crucially, common stages of an attack, including discovery, collection, exfiltration, and command-and-control, produced absolutely no output. This suggests a significant blind spot in the system’s ability to identify sophisticated or even basic malicious activities.

The author of this measurement acknowledges its limitations. It is not an independent benchmark and carries a self-correction: four of the 21 silent rows were re-evaluated. These were found to be measuring the observation window rather than the rule’s effectiveness, and are marked accordingly in the data. Nevertheless, the core finding remains: a standard, untuned SIEM deployment is unlikely to detect a significant portion of real-world attack vectors.

Why SIEMs Fail to Detect

The failure of SIEMs to detect a broad range of threats stems from several factors, primarily related to configuration, tuning, and the sheer complexity of modern attack methodologies. Out-of-the-box rulesets are often generic and designed to catch common, noisy events. They rarely account for the nuanced, low-and-slow techniques that attackers employ to remain undetected. Adversaries leverage techniques like living-off-the-land binaries, obfuscated scripts, and lateral movement that can appear as legitimate administrative activity if not specifically profiled and alerted upon.

Tuning is a labor-intensive process. It requires security analysts to understand the organization's specific environment, identify false positives, and develop custom rules to detect relevant threats. This process is ongoing, as attacker tactics evolve. The default Wazuh setup, like many other SIEM solutions, provides a foundation but requires significant investment in expertise and time to become an effective detection tool. Without this investment, the SIEM becomes little more than a log aggregation service, a digital black box that stores evidence but fails to raise the alarm when it matters most.

Consider the ATT&CK framework as a detailed playbook of adversary tactics and techniques. A SIEM's effectiveness is measured by its ability to recognize patterns within log data that correspond to these playbook entries. When a SIEM fails to alert on techniques like discovery (e.g., reconnaissance within the network) or exfiltration (e.g., data being silently copied out), it means that critical stages of an attack are passing by unnoticed. This is akin to having a security camera system that records everything but only flags a break-in if someone smashes a window, ignoring someone picking the lock and walking in.

MITRE ATT&CK matrix showing techniques, some of which were not detected by the SIEM.

The Cost of Ingestion Over Detection

The financial savings achieved by deploying a self-managed SIEM are often dwarfed by the potential costs of a security breach. When a SIEM fails to detect an intrusion, the response time increases dramatically. This delay allows attackers more time to move laterally, escalate privileges, exfiltrate data, and cause maximum damage. The subsequent incident response, forensic investigation, system recovery, and potential regulatory fines can far exceed the perceived savings from avoiding a managed security service provider (MSSP) or a more advanced detection platform.

The core issue is a misaligned understanding of what a SIEM provides. While it diligently ingests logs from various sources—endpoints, network devices, applications—this ingestion is merely the prerequisite for detection. It's the raw material, not the finished product. Without effective rules, analytics, and threat intelligence, the ingested data is just a historical record. The console showing green might signify that logs are arriving, but it says nothing about whether those logs contain indicators of compromise that are being acted upon.

For organizations that have invested in self-hosted SIEMs, the path forward involves a critical assessment of their detection capabilities. This means moving beyond the green dashboard and actively testing the SIEM's ability to detect known threats. Implementing red teaming exercises, utilizing threat emulation frameworks like ATT&CK, and regularly reviewing and tuning detection rules are essential steps. Failure to do so leaves the organization vulnerable, paying for a security tool that provides a false sense of security.

What Nobody Has Addressed Yet

What nobody has adequately addressed yet is the psychological impact of the green dashboard. Security teams, often understaffed and overworked, rely on visual cues like a green light to signify that their systems are functioning as intended. This reliance can foster complacency. The effort required to rigorously test and tune a SIEM is substantial, and when the system appears to be