Simple user-friendly features make our application as one of the most preferred one in the market.  Here, in this blog, we shall be posting on such user friendly features available in our product, which should sound simple and straight forward. These user friendly features took our users with some surprise, and hence advice you to put RSS to this blog post. (I should be updating this post quite often)

1.  Filter out events with Mouse gestures:

Position:  Drill down on any counts against the hosts configured, to grab them in a filtered view /export

Purpose: Filter out any events based on severity, or message strings, to create a quick report.

Let’s tour this feature now, and make your day easier with a sample scenario.

We know that, Eventlog Analyzer application is designed to report on Event logs, from hosts like Windows, Syslog devices (UNIX, Cisco’s, Solaris, Routers/Switches, etc) and application logs (SQL, IBM AS400, IIS and FTP server logs).

Our predefined reports are designed to provide you an overall picture of your enterprise’s activity (Compliance, Top N reports, etc).

For instance, you will see all the hosts collecting logs on ELA, and respective counts on severity, with log collection status on the Home tab itself.

Clicking on a host name should drill down to important events collected and counts of events.  Second level drill down should enable you to view in detail, exact transactions against the hosts. You can also export this page to a PDF or a CSV on demand. Again, I am sure, you are aware on this.

But, do you know we have a user friendly feature on this page, called Mouse gesture?

Try doing a mouse gesture by left clicking your mouse on any attributes, which will filter only the selection you have made, and export it to a PDF or CSV on demand.  You can do a second mouse gesture on this filtered search, to further drill down!! (Event ID is selected as 529, and message contains “a specific string” for unsuccessful user logons.). This feature is available for all the hosts, when you drill down for reports. Refer to some screen shots below.

Home tab

Host drill down

2nd level drill down


Mouse gesture


Here are a couple of scenarios for you to consider this user friendly feature.

  •      Creating a custom report based on Event Id’s with message filters is a time consuming, but one time affair. In reality, you at least have more than 1 try/attempt, to create a report based on your requirement. Now, you can use this feature by using your simple mouse clicks on any attributes available and do quick sample exports, then use the same attributes on your report profile, once done, and schedule it.  To be short, fill it, schedule it and get your reports based on your schedules.

  •     Consider a host with anomalous counts of failed logon and an IT manager should be interested on a report on such transactions (of course, we recommend creating alert profiles to get notifications on such instances).  All you do is drill down to these events, and either export this as a report on demand, or further filter out any important hosts/event id’s / or even message contents, on a couple of clicks, and the job is done. 

Sure, it should sound simple and straight forward. Try it out for yourself, and any feature request on this to be notified by email to eventloganalyzer-support@manageengine.com, with your contact information

Again, feel free to share your views and experience with us and let our experimenter get more ideas from you.

Regards
Shri
Eventlog Analyzer –team
Follow us on Twitter

The Economic Condition

After the down slide of US economy, there is lull now. Even the noted economist are not sure which way it will turn. Even in the uncertain economic times, the IT security cannot be compromised. It is a good sign that the companies are considering the IT/data security far too important. 

Gartner Survey Results

This is evidently clear from the results of the recent Gartner survey on budget allocation towards security software and services. Definitely there will be  an increase. It is around 4%. Even though there is an increase in budget, the increase is limited. But during the tough times, you do not have the luxury of big budget. The limited budget, the companies can set aside, need to be spent on the security software judiciously. This was reflected by the Gartner analysts in their report.

More Quality and Less Cost

SIEM is a major area, which is a proactive way of ensuring security. The companies have realized the benefit of being proactive when it comes to IT/data security. Hence, the results show the increase in budget (even though it is marginal) for security software. The emphasis is on limited increase in budget during these turbulent economic times. This means that the IT managers with budgetary powers, should look for the products/suites which offer real value for money. As such small and medium businesses are prudent in their security spending. Now it is time large enterprises to toe the SMB line and scout for enterprise grade, cost effective security solutions. They are not afford to spend their fortune to chase the reputed brand names for ensuring security.

ManageEngine Philosophy

ManageEngine, since inception believed in the philosophy of high quality and low cost (whether it is rain or shine in economy). IT Managers in your search for cost effective enterprise SIEM solutions, take note of ManageEngine suite. Yes, ManageEngine now offers enterprise grade (Distributed Edition) SIEM solutions. EventLog Analyzer, is an  event log management & regulatory compliance solution and Firewall Analyzer is a security event management & bandwidth monitoring solution. Take an informed decision during tough economic situations. Choose the right SIEM enterprise solutions complete in features and right in price.

Have a look at EventLog Analyzer Enterrpise Solution (Distributed Edition).

   

Running through my daily read lists, while on Network World Asia I came across the featured article 'How to maintain security without increasing the operational load on IT staff' by Joe Golden an IT manager. Golden's pain points were his increasing network load and minimal staffing to handle this load.

This didn't surprise me at all, I hear many IT managers and administrators with the same woes. More users are logging into the network, applications are many and devices of all types are jostling for network space. Almost like an out of control crowd at a rock concert with the bouncers trying their best to keep them storming the stage or from starting a brawl.They are valid ticket holders yet can disrupt the whole show. Its a hard job!

In addition, you've got backstage pass holders, crew members and all sorts of official pass holders who also need to move around the restricted areas. How's a bunch of tough looking bouncers going to manage it all?

Time for the reinforcements folks! Golden has listed out a few great pointers on how operational load can be reduced in some areas with the help of tools. One of them is the use of automated password reset tools which can save companies thousands of dollars and a huge amount of time as opposed to using help desk to perform the same task.

ManageEngine's ADSelfService Plus (ADSSP) is one such great password management tool. As the name suggests, ADSSP is completely self serviced enabling end users to reset their passwords bypassing the helpdesk. No more frantic midnight calls to helpdesk to reset a password.

Another area Golden finds that staff can be relieved from is Log compilation. Programs that automatically process log data to keep staff updated on any possible threat to the network can significantly reduce staff overload whilst ensuring greater security.

We couldn't have agreed more, sifting and analyzing logs are not what staff should be spending time on. Specially when you can get great reports and set up alerts by letting ManageEngine's EventLog  Analyzer do the laborious work.

Let ManageEngine act as the security guys at your network's concert.

Maybe now you and your staff will have more free time to go have some fun at a real concert than watch it on Youtube!

Go check out our goodies while I find tickets for the next concert.


Compliance is vital for any enterprise not merely to adhere to various regulatory/industry frameworks but also to mitigate the risks attached to corporate IT assets. Enterprises failing to comply not only face penalties from the regulatory bodies but also risk losing respectability and trust. However, in recent times many enterprises fail to remain fully compliant at all times which has led to many security breaches. Case in point, the recent Heartland breach highlighted the fact that staying compliant is a full-time process and just staying within the boundaries of a given regulatory framework is not sufficient to secure your network(s). Enterprises therefore need to look beyond the applicable frameworks to achieve compliance, and one important way is to analyze and manage system, application and event logs to prevent such huge incidents.

Log management for Compliance requirements is an increasingly vital process for enterprises across verticals. There are several implications to having an ineffective log management process, both tangible and intangible.

Enterprises that analyze their log data efficiently can easily recognize the value and impact on their IT and overall operations. The insight gained by log analysis and reporting can help enterprises determine their existing security implementation, cut down on costs on extensive regulatory audits and recovery measures, if any. Up to date log data analysis provides insight into the health and accessibility of network(s), system and applications.

A strong log management solution that handles voluminous and variety of logs is a necessary tool for enterprises to maintain the integrity of all data.

Let’s look at a checklist to ensure log management is applied effectively to ensure compliance.

Do’s

  1. Make Log management a daily routine and not just to satisfy compliance requirements

If log management is not done only for the sake of meeting regulatory requirements then we can cover our bases much more effectively. It will take care of any overlapping frameworks and reduce the time to meet all regulatory requirements. This will also cover any condition that is overlooked in the impression that another regulatory requirement covers it. Reports and alerts ensure that the security threat posed is brought to your attention, including those beyond the scope of regulatory compliance.


  1. Ensure alerts are set up as per the requirements of the enterprise

Ensure all alerts are set up correctly and for the specific requirements of the enterprise and not just to meet compliance requirements. If any critical data is suspected to have been accessed by an unauthorized user it must be alerted instead of ignoring it if it doesn’t meet a specific regulatory requirement. The alert set up must be reviewed and reassessed periodically.


  1. Review reports regularly to identify any gaps in the set up and regulatory requirements.

All reports must be checked not just for the expected data but also for any anomalies in them. Reports must be maintained also for what doesn’t meet the requirements and reviewed frequently.


  1. Conduct periodic tests to determine the effectiveness of the set up.

The network must be tested for effectiveness and efficiency in managing and analyzing logs in order to ensure that compliance requirements are met appropriately. A robust log management solution is a vital key towards staying compliant. The test must also be highlighted and validated by the system.


  1. Have a representative from the legal department to check if all regulatory requirements are understood and met by the IT department.

Not all regulatory requirements are easy to comprehend and hence might be misunderstood by those defining the IT compliance requirements. This is a pitfall that must be avoided hence all legal aspects must be simplified.


  1. Have a consistent approach to managing and analyzing the logs.

Make sure there are defined set of rules on how logs must be managed and analyzed. This must be dependent on the enterprise and not on the authorized personnel. If any change in authority takes place the set of rules for log handling mustn’t be changed as this can lead to loss of log data.


  1. Check for unauthorized programs installed by users within the network.

Most breaches are caused due to malicious code planted in the network through unauthorized programs. Users are mostly unaware of the potential threat in installing seemingly harmless programs. A log management solution can help detect such unauthorized programs and alert the administrator before any harm is done.

Don’ts

  1. Give access to unauthorized users to view, edit and delete any information.

Access to the network must be strictly monitored and only given to authorized members. Data should be classified appropriately and access to them regulated and monitored. All unauthorized access must be alerted promptly by the log management solution.


  1. Provision any Team/group access to any critical data.

No authorization must be provided on a team/group level as this is a greater exposure to risks and provide room for human error. Any changes made on one-on-one level will be lost if not communicated on team/group level.


  1. Keep unnecessary ports open in the network.

All redundant ports must be closed in the network(s) in order to protect it from any malicious attack. Ports must be periodically reviewed to ensure only those required are accessible.


  1. Run unused services in vital servers.

In order to keep the network(s) efficient and easy to manage all unused services must be stopped to avoid any conflict with essential services. Any redundant service poses a risk in interfering with the operation of critical resources, which will lead to failure of required processes.

This isn’t a comprehensive checklist of course but if you don’t have one, this might be a good place to start. Each enterprise needs to get started with log management with their customized set of checklists to ensure the enterprise IT network(s) is optimally secured. Merely being compliant isn’t enough; it also requires staying more vigilant and having stringent security measures in place.


Yes!

AdventNet ManageEngine is hosting Roadshows in countries across the European Union.

If security of your enterprise IT infrastructure is your concern, then you must visit ME Euro Roadshow 2008.

We are available in your town. Feel free to seek any information about EventLog Analyzer.  Join us at the Roadshow in your country, register here 

Check complete details about the Roadshow, visit the link: http://manageengine.adventnet.com/euroroadshow/

The ManageEngine Booth at the Interop Las Vegas 2008 was abuzz with activity.

You can see one of the esteemed EventLog Analyzer customer visiting the booth. They were happy with the product and the level of support (definitely AdventNet forte) offered.

EventLog Analyzer customer Interop Las Vegas 2008 booth

Our contact person VJ Karthik flanked by EventLog Analyzer customers.

Welcome!

Jul 10 2006 05:10:32 PM Posted By : ajaykumar
Comments (0)

Welcome to EventLog Analyzer Blogs!

It gives me immense pleasure to welcome you to the EventLog Analyzer team's scribblings. This would be our way of having informal exchanges about everything under the sun, which would of course include discussions on EventLog Analyzer.

Here, you would get to meet the young team behind this product, discuss with them and have some mutually wonderful learning experience.

Thank You

AJ