This document provides an overview of security analytics from the perspective of Simon Bennett, who works in networking and information security. It discusses the need for security as an IT service to prevent downtime, loss of reputation, data, and intellectual property from threats like DDoS attacks and malware infections. Security analytics is defined as examining all possible data sources, including technical logs, informational sources on the internet, and personal contacts, to glean intelligence. This intelligence can then be used to analyze firewall and other security device traffic logs to detect anomalies. The document also briefly outlines the history of firewalls and how next generation firewalls can implement more advanced policies than early stateful firewalls through powerful analysis of network traffic.