RE: Log Aggregation/SIEM solutions/Compliance

"Robert Rounsavall" <[email protected]>
Newsgroups gmane.comp.sysutils.loganalysis
Message-ID <2FC9EBF8D5275546AEEC4E9AEEE0444A019F25FE@EXCHANGE03.terremark.org>
Just deployed Activeworx SIM in a large production environment.  

 

Disclaimer: Used to work for the distributor of the product...

 

Basically it runs on a windows platform, has these collectors that
either query windows boxes via wmi, or you point your switches, routers,
IDS, etc at the collectors by a syslog entry and it normalizes and
shoves everything into a mysql database for analysis, archiving, etc.
Routers, switches, and the ISS IPS devices that we monitored both via
syslog and their site protector database with no major issues.  It is a
great tool for analyzing all your devices in one view.  We immediately
discovered some problems on the network due to misconfigured switches.
The main bottleneck that we had was the checkpoint firewall.  There was
so much traffic going through that it would fill up the mysql database
and crash after a day or so.  Like someone said earlier, you don't just
want to look at the dropped packets, you want to see what is getting
into your network as well, so when we were looking at all the traffic,
the collectors could handle the events no problem, but we had to do some
tuning on the database.  The key thing that we did was look at the
traffic, and apply some filters so that we weren't looking at everything
and more events of interest.  We set up automatic archiving so that in
the database where we are doing analysis, we are looking at only 24
hours of firewall events in the main view, but we are also able to
archive automatically anything older than a day.  Analysis tools are
good and it has a nice interface that lets you do a lot of cool things
such as event correlation with vulnerability scans from nessus, retina,
etc.  Also if you are running Snort as your IDS you can use IDS Policy
Manager to manage all the rules.  If you are looking for a do it
yourself type solution that is pretty easy to get up and running it
might be the way to go.  If you are looking at something you can just
drop on the network without building a server and take in loads and
loads of events with little or no tuning, then it isn't the best
solution.  I'm happy with what we are seeing right now after some pain
getting control of the firewall events.  It will work in a high volume
environment if it is distributed, meaning different collectors on
different networks.  Also when I say high volume, I guess it's relative,
but I just fired up the Arbor box on the network to see what kind of
volume we are running and our flow data is showing about 200 gigs of
traffic in a 24 hour period.  It's hard to test a lot of this stuff out
in a lab and get an excellent view of how things actually will behave on
the network 100% before dropping some change.  It's pretty standard
practice for the vendors who have hardware solutions to ship you out a
box for testing.  There are a lot of smart guys and gals on this list
who can make other recommendations as well.  I am glad to see it pick up
a bit again as well... I almost forgot I was a member for a while there!
Good luck and I hope this helped...

 

R

 

Robert Rounsavall, GCIA, GCWN
Product Manager - Security Services

 

Terremark Worldwide, Inc.
50 NE 9th St. Miami, Fl 33133
www.terremark.com

786-281-9751 cell
786-871-2326 direct
305-856-8190 fax
[email protected]

This information contained in this email transmission is private,
privileged and confidential.  It is intended only for the above named
recipient.  If the reader of this transmission is not the specified
recipient, you are hereby notified and warned that any dissemination,
discussion, reproduction, distribution or photocopy of this transmission
and its contents are deemed unauthorized and prohibited by state and
federal law.  If you have received this transmission in error, please
inform us promptly by replying to this email, then deleting this email
and all attachments and destroying any printed copies. Thank you.

________________________________

From: [email protected]
[mailto:[email protected]] On Behalf Of Bill Clark
Sent: Thursday, March 29, 2007 3:04 PM
To: [email protected]
Subject: [logs] Log Aggregation/SIEM solutions/Compliance

 

Since the list has picked up a bit again.  I thought I would throw
something out there for opinions. I am looking to solve many similar
problems possibly in one product.  One need is a tool to allow many
different types of people to view collections or classes of log events
in one place.  Currently we have number of different centralized
collection points.  One place for all snort senors, one place for all
firewall logs, one for all Unix servers, one for all Windows Servers,
One for all Identity Management events, etc.. you get the idea.  

We want a tool for Security oversight, Compliance and Operational
benefits.
At the same time attesting to log reviews for compliance has become
quite tedious.  And there is a need for better automated workflow and
notification of all these logs.  Originally I thought we might develop
this in-house perhaps leveraging an Opensource tool.  But we have found
that there is a tool out there we think will do most of this with the
money we had budgeted to do this ourselves.  And if we went with it we
could start benefiting sooner.  

We have identified the Novell acquisition of e-Security's Sentinel
product.  We like that it is agent less with some light agent support
and the correlation rules are PCRE like.  The collectors appear to meet
most of our needs with flexibility to add custom ones.  The architecture
also seems scalable with a Message-bus feeding a database.  And the
database is pretty open. 

I don't want turn this into a product pimping session.  I am looking for
opinions of people that have looked at it, used it, or have other better
ideas commercial or Opensource.  Arcsight was ruled out early because of
cost and not looking very open.  I won't get into specific requirements
as this isn't an RFP. 

-- 
Bill Clark
wwclarkATgmailDOTcom

_______________________________________________
LogAnalysis mailing list
[email protected]
http://www.loganalysis.org/mailman/listinfo/loganalysis
image001.jpg (image/jpeg, 2.5 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.