This is a very interesting subject to me. During incidents, you often want every single event you can find. The better the visibility the more complete the picture, much like more pixels make a better photo. However, the SIEM vendors charge by EPS and/or amount of data stored/indexed. Seems sort of like going to a doctor and asking to know what is wrong but only mentioning one symptom of many. I have found many times that users locking screens, screen savers activating, temp files being deleted, etc. can clarify exactly what is going on.
The same applies to firewalls, coalescing events; particularly on things like web servers, where the urls being accessed change but only the first events are kept. The EPS is the same either way, but storing the events of course costs more. But isn't storage cheap these days?
I'm not a huge proponent of filtering events. But at the same time there are realities in costs, CPU, storage, licenses etc. But after an incident, would business management be more interesting in keeping all events, much as they do in accounting.... Accounts Payable, Receivables, etc are all rolled up to general ledger, but those details are never purged for years.
Just some thoughts on the matter.
------------------------------
Frank Eargle
------------------------------