Advanced Security Analytics Module (ASAM), is one of the most significant Add-Ons for any enterprise class network looking to utilize flow based monitoring technology. Without any additional hardware or export configurations, this simple Add-On to NetFlow Analyzer can act as your network Intrusion Detection System leveraging on the prevailing flow data collection in place.

Compelling reasons to choose a flow based security analytics system over complex and expensive signature based threat detection systems is ease of deployment and cost effectiveness. ASAM does not require any base lining period and manual intervention for it to detect network anomalies. ASAM starts reporting on anomaly events immediately after the installation of the module.

Below are the salient features of the ASAM Add-On for NetFlow Analyzer:

1. Real time threat detection

      ASAM, built using the state-of-the-art "Continuous Stream Miner" technology, helps identify numerous threats in your network in real time. The underlying engine is optimized for scalability with very less memory and CPU footprints.

2. Security Snapshot Report

      Security snapshot gives you a quick understanding of different types of intrusion activities over a configurable time period.

                
                

3. Highly Customizable 

      Discarding and White listing based on 

                  * Security Events
                  * IP addresses
                  * Flows matching specific criteria

      ASAM, giving more power to the you, helps see threats based on your specific requirements also. Ensures near zero false positives occur by filtering known good data. 

      Additionally ASAM does not require signature or pattern definition updates to detect security threats, instead the analytics engine is capable of identifying threats by correlating transactions using a robust "date time span offset" clustering algorithm, delimited based on active and inactive time outs and threshold violations for various flow fields.
 
To know more about ASAM and the anomaly types detected by ASAM, check the link here.

Try the 30 day fully featured trial of NetFlow Analyzer with ASAM Add-On. Feel free to talk to the support team for any questions on NetFlow Analyzer and ASAM.


Thanks

VMware Performance Monitoring - the Must Haves

Jul 26 2010 08:46:33 AM Posted By : sreelesh
Monitoring and optimizing virtualized server infrastructure requires a different, more detailed approach from that with physical servers. While the 70+ deep VMware monitors in OpManager’s VMware monitoring add-on may seem overwhelming for some administrators, these could at the same time be insufficient for some!

If you are starting out with virtualization using VMware or are overwhelmed with the intricacies involved in diagnosing poor VM/host performance, we have just the right twenty minutes to make things easier for you. Do join us for a webinar on “VMware Performance Monitoring – the Must haves” on Wednesday and Thursday in the timings shown below and we’ll give you a quick rundown on some of the most critical parameters that need to be monitored over VMware infrastructure.

Topic: VMware performance monitoring - the Must Haves.

Schedule: Register for any one of the following sessions:

Applications Manager makes VMware monitoring easy

Jul 23 2010 08:21:51 AM Posted By : Arun B
We’ve released version 9.2 of ManageEngine Applications Manager and the main highlight of this release is VMware monitoring. We now provide out-of-the-box support for monitoring VMware ESX/ESXi host servers as well as their guest virtual machine instances.

As you probably know, server virtualization offers many benefits and many enterprises are undertaking virtualization of their IT infrastructure in order to make the most of these benefits. VMware is probably the leading vendor of virtualization software. VMware ESX and ESXi servers are the most widely deployed hypervisors.  So it makes good sense to monitor the performance and health of your VMware ESX and ESXi servers in order to ensure your virtual infrastructure is performing as expected.

What do we monitor?

Apart from monitoring the availability and overall performance of the ESX/ESXi servers, we provide in-depth metrics for performance indicators such as

CPU Utilization - get combined CPU usage of ESX server, CPU used by the virtual machines configured to the server, CPU utilization of cores, etc.

Memory Utilization - including metrics such as consumed memory, active memory, granted memory, overhead memory, shared memory, reserved memory, etc.

Metrics pertaining to the data stores of the server

Network utilization stats such as Data transfer/receive rate, packets received/ transmitted, etc.

Disk I/O stats such as disk read/write rate, health



You can also get an idea of the top ESX/ESXi servers in your network in terms of resources consumed.  Metrics provided include Top CPU consumers, Top Memory Consumers, Top Disk I/O consumers and Top Network consumers.



While these metrics give you insight into the performance of the server, we also provide a lot of meaningful metrics for the virtual machines associated to each of these servers. This makes troubleshooting easier as you can quickly identify which component is having a problem. These along with powerful reports such as the one shown below can help you analyze VMware server performance trends, and maintain optimal performance of your VMware infrastructure.



The VMware monitoring capability is available as an add-on to Applications Manager and works with both Professional and Enterprise editions. You can download a 30-day free trial of Applications Manager to check out the new VMware monitoring capabilities. If you already use Applications Manager, you need to install the latest service pack to gain access to VMware monitor.

Configuring Cisco ASA NetFlow via ASDM

Jul 22 2010 06:20:40 AM Posted By : Praveen Kumar V

All of you must have already heard about Cisco ASA now supporting NetFlow export through a flow format called NetFlow Secure Event Logging (NSEL ). This now provides users the ability to do almost real time traffic analysis and bandwidth monitoring on their firewall devices too. NetFlow support from ASA received very excellent responses from users because of which we at NetFlow Analyzer started support for not just plain ASA NetFlow reports but also for NATed information available in the ASA NetFlow packets.

With NetFlow support, I am sure a number of users out there will like to know the best and easiest way to configure ASA for NetFlow export. Check out the steps below to configure NetFlow export on ASA via ASDM:

Configuring Flow Collector:

In ASDM, under Configuration go to Device Management > Logging > NetFlow


Here, you can set the NetFlow Analyzer server IP address, the ASA interface through which NetFlow packets are to be exported and the NetFlow listener port (By default it is 9996). When you choose the interface, select the interface which connects to the server where NetFlow Analyzer is installed. You can also set the template packet send frequency and disable syslogs that are redundant after the NetFlow information extraction.

Set the template time out rate as 1 minute and delay transmission of flow creation events for short-lived flows to be 60 seconds.


Then click on Apply to write the commands on ASA.

Configuring NetFlow information extraction:

To enable the ASA to start sending information to the NetFlow Analyzer defined above you need to go to Firewall > Service Policy Rules.


Then you need to create a new service policy that needs to be applied GLOBALLY.


And then define the collector that statistics for this traffic will be sent to (was defined initially).

Once the service policy is created click on Apply to write the commands on ASA.


To configure Cisco ASA through CLI click here .

Once the configuration is complete, NetFlow data will be exported and you will start seeing results in NetFlow Analyzer.

Demo | Download 30-day Trial Twitter  | Customers

Regards,
Praveen Kumar

Greetings from ManageEngine Desktop Central

We are happy to announce the availability of latest hotfix to Desktop Central 7 - Build 70117. Here's the complete list of enhancements & bug fixes from the previous hotfix:

Enhancements & Bug Fixes

Enhancements

  1. Hardware details of CDROM Drive, USB Controller and USB Hub will now have an additional column indicating the reason for the hardware error, if any.
  2. Option to grant/revoke remote access to the database used by Desktop Central for users to retrieve the data for reporting purposes has been included.
  3. Patch engine has been optimised for large networks.

Bug Fixes

  1. Distribution Server patch replication issue has been fixed.
  2. Issue in performing double-click actions twice on the Remote Computer when using Java Viewer has been fixed.
  3. Num Lock key issue on the Remote Computer when accessing it using the Activex viewer has been fixed.

You can download the hotfix and install as per the instructions provided there.

To download complete product, which includes these enhancements, visit our website.

Patch Engine Optimized to Improve Performance

The Patch Engine of Desktop Central has been optimized to improve the performance by reducing the CPU usage. This will considerably reduce the load on the Server, which can be used to run any additional applications.

What's Cooking?

The features in our roadmap that are currently under development include:

  • Approval Mechanism for Automatic Uninstallation of Prohibited Software Details>>
  • Automating Software Deployment Details>>
  • Active Directory Authentication - Logging into Desktop Central client will be authenticated via Windows Active Directory

Add Requirements to Product Roadmap

You can add your new feature requirements on Desktop Management to our roadmap. We will prioritize and include them in our subsequent updates. Visit our Roadmap and add your requirements.

WindowsITPro has recently opened the nominations for 2010 Community Choice Awards. We request your support to nominate ManageEngine Products for the awards.

Following is the list of categories opened for nomination and products from ManageEngine that serve under each category:
 > Best Active Directory - ManageEngine ADManager Plus
 > Best Auditing/Compliance Product - ManageEngine ADAudit Plus / ManageEngine EventLog Analyzer / ManageEngine Firewall Analyzer
 > Best Deployment/Configuration Product - ManageEngine DeviceExpert
 > Best Management Suite - ManageEngine IT360
 > Best Network Management / Monitoring Product - ManageEngine OpManager
 > Best Patch Management Product - ManageEngine Desktop Central
 > Best Security Product - ManageEngine Security Manager Plus
 > Best Virtualization Product - ManageEngine OpManager
 > Best Systems Monitoring - ManageEngine OpManager
 > Best Free Tool - ManageEngine VMHealth Monitor
 > Best Vendor Support - ManageEngine

Click here to nominate.


Regards,
Bharani
Microsoft has released 4 new security bulletins for the July 2010  edition of patch Tuesday. These 4 bulletins address 5 vulnerabilities. 

Our patch assessment team has completed the testing of the following security bulletins and updated the Central Repository Server.

MS10-042, MS10-043, MS10-044,  and MS10-045

Synchronize the vulnerability database in the desktop central web console under the Patch Mgmt tab to update the local database.

Deployment Priority (Courtesy: MSRC Blog )

July 2010 Risk and Impact



July 2010 Deployment Priority


In addition to this month patch releases, Microsoft has also re-release their MS10-024 bulletin. The patches of this re-release has also been updated in Desktop Central.

For any assistance on patching feel free to contact desktopcentral-support@manageengine.com

Happy Patching. 

cheers,

Can Paul the Octopus predict IT failures?

Jul 09 2010 10:10:34 PM Posted By : sreelesh
Octopus Paul


It's the weekend that hosts the best football played in the past four years - Germany takes on Uruguay for 3rd play-offs and Spain fights Netherlands for the grand World Football Champions title. Octopus Paul who's been on a 100% success rate in his predictions so far at FIFA 2010, says that Germany and Spain win in their respective games. And having seen these four teams play I too think it's Spain-Netherlands-Germany-Uruguay placed 1-2-3-4. So Paul will remain 100% successful in his predictions this worldcup?!!

What if you had magical, psychic Octopus Paul solving IT failures for you? Check out what we think at http://www.manageengine.com/network-monitoring/ .. After the football weekend, after you've cooled off, do the latest OpManager 8.7 and make yourself magical & psychic with IT!

Get the beers & chips in stock and have a great football weekend folks!



 
DeviceExpert - Automation

It is often said: “Change is the enemy of network availability”.  Human errors on network device configuration often lead to network outages spoiling business continuity. Aside, highly skilled network administrators often spend all their time on manually managing the configurations and changes. Typically, repetitive tasks such as modifying VLAN settings, changing access control lists, rotating passwords, firmware upgrades and the like eat away the time and efforts of administrators. They get little time to concentrate on real network administration - ensuring security and reliability, compliance to best practices and IT regulations, optimizing performance, capacity and utilization of the network.

ManageEngine DeviceExpert helps you automate and simplify the entire life cycle of Network Change & Configuration Management (NCCM). DeviceExpert significantly saves your time, cost and resources, reduces the risk of errors and network downtime and thereby improves efficiency and productivity. DeviceExpert also integrates with OpManager. Try DeviceExpert / OpManager NCM Plug-in now!

Bala
ManageEngine DeviceExeprt

Take action on Search Results

Jul 06 2010 05:16:19 AM Posted By : Gibu
You must be already aware of Release 9.2 of Applications Manager with VMWare Monitoring , Memcached Monitoring and PostgreSQL Monitoring .

Another silent enhancement we made in the previous release in addition to the popular anomaly detection and enhanced alarm management capabilities is the ability to take action on the search results.

We observed many of our customers with large number of monitors preferred to use the older search to reach the monitor. Now we decided to allow them to even take some action on the search results.

Now you can search for a keyword like "server" or "mysql" etc and you can take action on the results. The results show up with the Bulk Edit view that makes it easier to take action.


action on search results

Some of the actions you can perform in bulk on the search results are updating display names, poll intervals, Manage/ UnManage, updating passwords, IP Address etc.

If there is something that you think will make life easy for you while using Applications Manager, do post your comments or vote your idea up, via our community portal.

Gibu

ManageEngine Applications Manager
Application Performance Monitoring Tool