RE: Log Aggregation/SIEM solutions/Compliance
"Robert Rounsavall" <[email protected]>
| Newsgroups | gmane.comp.sysutils.loganalysis |
|---|---|
| Message-ID | <2FC9EBF8D5275546AEEC4E9AEEE0444A019F25FE@EXCHANGE03.terremark.org> |
Just deployed Activeworx SIM in a large production environment. Disclaimer: Used to work for the distributor of the product... Basically it runs on a windows platform, has these collectors that either query windows boxes via wmi, or you point your switches, routers, IDS, etc at the collectors by a syslog entry and it normalizes and shoves everything into a mysql database for analysis, archiving, etc. Routers, switches, and the ISS IPS devices that we monitored both via syslog and their site protector database with no major issues. It is a great tool for analyzing all your devices in one view. We immediately discovered some problems on the network due to misconfigured switches. The main bottleneck that we had was the checkpoint firewall. There was so much traffic going through that it would fill up the mysql database and crash after a day or so. Like someone said earlier, you don't just want to look at the dropped packets, you want to see what is getting into your network as well, so when we were looking at all the traffic, the collectors could handle the events no problem, but we had to do some tuning on the database. The key thing that we did was look at the traffic, and apply some filters so that we weren't looking at everything and more events of interest. We set up automatic archiving so that in the database where we are doing analysis, we are looking at only 24 hours of firewall events in the main view, but we are also able to archive automatically anything older than a day. Analysis tools are good and it has a nice interface that lets you do a lot of cool things such as event correlation with vulnerability scans from nessus, retina, etc. Also if you are running Snort as your IDS you can use IDS Policy Manager to manage all the rules. If you are looking for a do it yourself type solution that is pretty easy to get up and running it might be the way to go. If you are looking at something you can just drop on the network without building a server and take in loads and loads of events with little or no tuning, then it isn't the best solution. I'm happy with what we are seeing right now after some pain getting control of the firewall events. It will work in a high volume environment if it is distributed, meaning different collectors on different networks. Also when I say high volume, I guess it's relative, but I just fired up the Arbor box on the network to see what kind of volume we are running and our flow data is showing about 200 gigs of traffic in a 24 hour period. It's hard to test a lot of this stuff out in a lab and get an excellent view of how things actually will behave on the network 100% before dropping some change. It's pretty standard practice for the vendors who have hardware solutions to ship you out a box for testing. There are a lot of smart guys and gals on this list who can make other recommendations as well. I am glad to see it pick up a bit again as well... I almost forgot I was a member for a while there! Good luck and I hope this helped... R Robert Rounsavall, GCIA, GCWN Product Manager - Security Services Terremark Worldwide, Inc. 50 NE 9th St. Miami, Fl 33133 www.terremark.com 786-281-9751 cell 786-871-2326 direct 305-856-8190 fax [email protected] This information contained in this email transmission is private, privileged and confidential. It is intended only for the above named recipient. If the reader of this transmission is not the specified recipient, you are hereby notified and warned that any dissemination, discussion, reproduction, distribution or photocopy of this transmission and its contents are deemed unauthorized and prohibited by state and federal law. If you have received this transmission in error, please inform us promptly by replying to this email, then deleting this email and all attachments and destroying any printed copies. Thank you. ________________________________ From: [email protected] [mailto:[email protected]] On Behalf Of Bill Clark Sent: Thursday, March 29, 2007 3:04 PM To: [email protected] Subject: [logs] Log Aggregation/SIEM solutions/Compliance Since the list has picked up a bit again. I thought I would throw something out there for opinions. I am looking to solve many similar problems possibly in one product. One need is a tool to allow many different types of people to view collections or classes of log events in one place. Currently we have number of different centralized collection points. One place for all snort senors, one place for all firewall logs, one for all Unix servers, one for all Windows Servers, One for all Identity Management events, etc.. you get the idea. We want a tool for Security oversight, Compliance and Operational benefits. At the same time attesting to log reviews for compliance has become quite tedious. And there is a need for better automated workflow and notification of all these logs. Originally I thought we might develop this in-house perhaps leveraging an Opensource tool. But we have found that there is a tool out there we think will do most of this with the money we had budgeted to do this ourselves. And if we went with it we could start benefiting sooner. We have identified the Novell acquisition of e-Security's Sentinel product. We like that it is agent less with some light agent support and the correlation rules are PCRE like. The collectors appear to meet most of our needs with flexibility to add custom ones. The architecture also seems scalable with a Message-bus feeding a database. And the database is pretty open. I don't want turn this into a product pimping session. I am looking for opinions of people that have looked at it, used it, or have other better ideas commercial or Opensource. Arcsight was ruled out early because of cost and not looking very open. I won't get into specific requirements as this isn't an RFP. -- Bill Clark wwclarkATgmailDOTcom _______________________________________________ LogAnalysis mailing list [email protected] http://www.loganalysis.org/mailman/listinfo/loganalysis
image001.jpg
(image/jpeg, 2.5 KB) - not displayed