<rss version="2.0"
 	 xmlns:dc="http://purl.org/dc/elements/1.1/"
 	 xmlns:atom="http://www.w3.org/2005/Atom">

	<channel>
		<title>Enterprise IT Management, Network performance management, IT Servicedesk, Desktop Management, Datacenter Management,  Server Management, Log Analysis and Security Management, Network Tools, ManageEngine Blogs</title>
		<atom:link href="http://blogs.manageengine.com/eventloganalyzer/feed" rel="self" type="application/rss+xml"/>
		<link>http://blogs.manageengine.com/eventloganalyzer</link>
		<description><![CDATA[Blogs from ManageEngine, written by product experts, on enterprise IT management]]></description>
		<pubDate>Sat, 7 Nov 2009 17:09:39 -0800</pubDate>

		<item>
			<title>Do you know about Mouse gestures on Eventlog Analyzer v.6?</title>
			<link>http://blogs.manageengine.com/eventloganalyzer/2009/10/21/do-you-know-about-mouse-gestures-on-eventlog-analyzer-v-6</link>
			<dc:creator>Shri Shankar</dc:creator>
			<description><![CDATA[<p>Simple
user-friendly features make our application as one of the most
preferred one in the market.&nbsp; Here, in this blog, we shall be posting
on such user friendly features available in our product, which should
sound simple and straight forward. These user friendly features took
our users with some surprise, and hence advice you to put RSS to this
blog post. (I should be updating this post quite often)<br clear="none"></p>
<p>1.&nbsp; <u>Filter out events with<span style="font-weight: bold;"> Mouse gestures</span></u><span style="font-weight: bold;">:</span></p>
<p><b>Position:</b> &nbsp;Drill down on any counts against the hosts configured, to grab them in a filtered view /export</p>
        
<p><b>Purpose:</b> Filter out any events based on severity, or message strings, to create a quick report. </p>
 
<p>Let’s tour this feature now, and make your day easier with a sample scenario. </p>
<p>We
know that, Eventlog Analyzer application is designed to report on Event
logs, from hosts like Windows, Syslog devices (UNIX, Cisco’s, Solaris,
Routers/Switches, etc) and application logs (SQL, IBM AS400, IIS and
FTP server logs).</p>
    
<p>Our predefined reports are designed to provide you an <b>overall picture of your enterprise’s activity</b> (Compliance, Top N reports, etc). </p>
    
<p>For
instance, you will see all the hosts collecting logs on ELA, and
respective counts on severity, with log collection status on the Home
tab itself. </p>
    
<p>Clicking on a host name should drill down to
important events collected and counts of events.&nbsp; Second level drill
down should enable you to view in detail, exact transactions against
the hosts. You can also export this page to a PDF or a CSV on demand.
Again, I am sure, you are aware on this. </p>
    
<p>But, do you know we have a user friendly feature on this page, <b>called Mouse gesture?</b></p>
 
<p> </p>
<p>Try doing a mouse gesture by left clicking your mouse on any <b>attributes, which will filter only the selection you have made</b>, and export it to a PDF or CSV on demand. &nbsp;<b>You can do a second mouse gesture on this filtered search, to further drill down!!</b>
(Event ID is selected as 529, and message contains “a specific string”
for unsuccessful user logons.). This feature is available for all the
hosts, when you drill down for reports. Refer to some screen shots below.<br></p><p><span></span><span><a href="http://blogs.manageengine.com/image/501000000107589/home-tab.png"><img src="http://blogs.manageengine.com/image/501000000107591/home%20tab.png" alt="Home tab" title="Home tab" style="border: 4px solid rgb(239, 239, 239); margin: 0px 2px; padding: 4px; width: 272px; height: 160px;"></a></span><br></p><p><span></span><span></span><span><span></span></span><span><a href="http://blogs.manageengine.com/image/501000000107593/1st-drill-down.png"><img src="http://blogs.manageengine.com/image/501000000107595/1st%20drill%20down.png" alt="Host drill down" title="Host drill down" style="border: 4px solid rgb(239, 239, 239); margin: 0px 2px; padding: 4px; width: 263px; height: 148px;"></a></span><br></p><p><span><a href="http://blogs.manageengine.com/image/501000000107597/2nd-drill-down.png"><img src="http://blogs.manageengine.com/image/501000000107599/2nd%20drill%20down.png" alt="2nd level drill down" title="2nd level drill down" style="border: 4px solid rgb(239, 239, 239); margin: 0px 2px; padding: 4px;"></a></span><br></p>
<br><span><a href="http://blogs.manageengine.com/image/501000000107605/mouse-guesture-1.png"><img src="http://blogs.manageengine.com/image/501000000107607/mouse%20guesture%201.png" alt="Mouse gesture" title="Mouse gesture" style="border: 4px solid rgb(239, 239, 239); margin: 0px 2px; padding: 4px;"></a></span><br><br><br>Here are a couple of scenarios for you to consider this user friendly feature.<br clear="none">
<br clear="none"><ul><li>
&nbsp;&nbsp;&nbsp;&nbsp; Creating a custom report based on Event Id’s with message filters is a time
consuming, but one time affair. In reality, you at least have more than
1 try/attempt, to create a report based on your requirement. Now, you
can use this feature by using your simple mouse clicks on any
attributes available and do quick sample exports, then use the same
attributes on your report profile, once done, and schedule it.&nbsp; To be
short, fill it, schedule it and get your reports based on your
schedules.</li></ul><br><ul><li>
&nbsp;&nbsp;&nbsp; Consider a host with anomalous counts of failed logon and an IT
manager should be interested on a report on such transactions (of
course, we recommend <span style="font-weight: bold;">creating alert profiles</span> to get notifications on
such instances).&nbsp; All you do is drill down to these events, and either
export this as a report on demand, or further filter out any important
hosts/event id’s / or even message contents, on a couple of clicks, and
the job is done.&nbsp; </li></ul>


<br clear="none">
Sure, it should
sound simple and straight forward. Try it out for yourself, and any
feature request on this to be notified by email to <span><a href="http://www.manageengine.com/products/eventlog/request-support.html" target="_blank" rel="http://www.manageengine.com/products/eventlog/request-support.html">eventloganalyzer-support@manageengine.com</a></span>, 
with your contact information<br clear="none">
<br clear="none">Again, feel free to share your views and experience with us and let our experimenter get more ideas from you.<br clear="none">
<br clear="none">
Regards<br clear="none">
Shri<br clear="none">
Eventlog Analyzer –team<br>Follow us on <span><a href="http://twitter.com/LogGuru/" target="_blank" rel="http://twitter.com/LogGuru/">Twitter</a></span>]]></description>
			<category><![CDATA[General]]></category>
			<guid isPermaLink="true">http://blogs.manageengine.com/eventloganalyzer/2009/10/21/do-you-know-about-mouse-gestures-on-eventlog-analyzer-v-6</guid>
			<pubDate>Wed, 21 Oct 2009 06:34:16 -0700</pubDate>
		</item>

		<item>
			<title>Security Software Spending and Uncertain Times of Economy</title>
			<link>http://blogs.manageengine.com/eventloganalyzer/2009/10/02/software-security-spending-and-uncertain-times-of-economy</link>
			<dc:creator>Ragavan S</dc:creator>
			<description><![CDATA[<p style="font-weight: bold;">The Economic Condition<br></p><p>After the down slide of US economy, there is lull now. Even
the noted economist are not sure which way it will turn. Even in the uncertain economic times,
the IT security cannot be compromised. It is a good sign that the
companies are considering the IT/data security far too important.&nbsp;</p><p><span style="font-weight: bold;">Gartner Survey Results</span><br></p><p>This is
evidently clear from the results of the <a linkindex="26" _prevhref="" href="http://biztech2.in.com/india/news/security/security-software-services-budgets-to-increase-four-percent-in-2010/64922/0" zid="40">recent Gartner survey</a> on budget allocation towards security software and services. Definitely there will be&nbsp; an increase. It is around 4%. Even though there is an increase in budget, the increase is limited. But
during the tough times, you do not have the luxury of big budget. The limited budget, the companies can set aside, need to be spent on the security software judiciously. This was reflected by the Gartner analysts
in their report. <br zid="17"></p><span style="font-weight: bold;">More Quality and Less Cost</span><br style="font-weight: bold;"><br zid="35">SIEM
is a major area, which is a proactive way of ensuring security. The
companies have realized the benefit of being proactive when it comes to
IT/data security. Hence, the results show the increase in budget (even though it is marginal) for
security software. The
emphasis is on limited increase in budget during these turbulent
economic times. This means that the IT managers with budgetary powers,
should look for the products/suites which offer real value for money.
As such small and medium businesses are prudent in their security
spending. Now it is time large enterprises to toe the SMB line and
scout for enterprise grade, cost effective security solutions. They are
not afford to spend their fortune to chase the reputed brand names for
ensuring security.<br><br><span style="font-weight: bold;">ManageEngine Philosophy</span><br style="font-weight: bold;" zid="41"><br zid="42">ManageEngine, since inception believed in the philosophy of high quality and low cost (whether it is rain or shine in economy). IT Managers in your search
for cost effective enterprise SIEM solutions, take note of ManageEngine
suite. Yes, ManageEngine now offers enterprise grade (Distributed
Edition) SIEM solutions. EventLog Analyzer, is an&nbsp; event log management
&amp; regulatory compliance solution and Firewall Analyzer is a
security event management &amp; bandwidth monitoring solution. Take
an informed decision during tough economic situations. Choose the right
SIEM enterprise solutions complete in features and right in price.<br zid="43"><br zid="44">Have a look at <a linkindex="27" _prevhref="" href="http://www.manageengine.com/products/eventlog/distributed-monitoring/index.html" zid="49">EventLog Analyzer Enterrpise Solution (Distributed Edition)</a>.<br zid="45"><br zid="46">&nbsp; &nbsp; <br zid="3">]]></description>
			<category><![CDATA[General]]></category>
			<guid isPermaLink="true">http://blogs.manageengine.com/eventloganalyzer/2009/10/02/software-security-spending-and-uncertain-times-of-economy</guid>
			<pubDate>Fri, 2 Oct 2009 08:33:09 -0700</pubDate>
		</item>

		<item>
			<title>Security Vs Operational efficiency - Striking the balance with productive tools</title>
			<link>http://blogs.manageengine.com/eventloganalyzer/2009/07/09/security-vs-operational-efficiency-striking-the-balance-with-productive-tools</link>
			<dc:creator>Pooja Sengupta</dc:creator>
			<description><![CDATA[<p style="text-align: justify;"></p><div>


</div><div style="text-align: justify;">


</div><p style="text-align: justify;">Running through my daily read lists, while on Network World Asia I came across the featured article '<a zid="50" href="http://www.networksasia.net/content/how-maintain-security-without-increasing-operational-load-it-staff?page=0%2C0"><span zid="9" style="font-style: italic;">How to maintain security without increasing the operational load on IT staff</span></a>' by Joe Golden an IT manager. Golden's pain points were his increasing network load and minimal staffing to handle this load.</p><p style="text-align: justify;">This didn't surprise me at all, I hear many IT managers and
administrators with the same woes. More users are logging into the
network, applications are many and devices of all types are jostling
for network space. Almost
like an out of control crowd at a rock concert with the bouncers trying
their best to keep them storming the stage or from starting a
brawl.They are valid ticket holders yet can disrupt the whole show. Its
a hard job!</p><p style="text-align: justify;">In addition, you've got backstage pass holders, crew members and all
sorts of official pass holders who also need to move around the
restricted areas. How's a bunch of tough looking bouncers going to
manage it all?</p><p style="text-align: justify;">Time for the reinforcements folks! Golden has listed out a few great
pointers on how operational load can be reduced in some areas with the
help of tools. One of them is the use of automated password reset tools which can save companies thousands of dollars and a huge amount of time as opposed to using help desk to perform the same task.</p><div style="text-align: justify;">


</div><p style="text-align: justify;"><span style="font-weight: bold;">ManageEngine</span>'s <a style="font-weight: bold;" zid="74" href="http://www.manageengine.com/products/self-service-password/index.html">ADSelfService Plus</a>
(ADSSP) is one such great password management tool. As the name
suggests, ADSSP is completely self serviced enabling end users to reset
their passwords bypassing the helpdesk. No more frantic midnight calls
to helpdesk to reset a password.</p><p style="text-align: justify;">Another area Golden finds that staff can be relieved from is Log
compilation. Programs that automatically process log data to keep staff
updated on any possible threat to the network can significantly reduce
staff overload whilst ensuring greater security.</p><div style="text-align: justify;">
</div><p style="text-align: justify;">We couldn't have agreed more, sifting and analyzing logs are not what
staff should be spending time on. Specially when you can get great
reports and set up alerts by letting <span style="font-weight: bold;">ManageEngine</span>'s <a style="font-weight: bold;" zid="75" href="http://www.eventloganalyzer.com/">EventLog&nbsp; Analyzer</a> do the laborious work.</p><div style="text-align: justify;">


</div><p style="text-align: justify;">Let ManageEngine act as the security guys at your network's concert.</p><div style="text-align: justify;">

</div><p style="text-align: justify;">Maybe now you and your staff will have more free time to go have some fun at a real concert than watch it on Youtube!</p><p style="text-align: justify;">Go check out our <span zid="81"><a zid="82" href="http://www.manageengine.com/" title="http://www.manageengine.com" target="_blank">goodies</a></span> while I find tickets for the next concert. <img src="/images/smiley/smiley-wink.gif"></p><p style="text-align: justify;"><span><a href="http://www.twitter.com/pooja4logs"><img src="http://blogs.manageengine.com/image/501000000056207/twitteranime2.gif" style=""></a></span><br></p><p></p>]]></description>
			<category><![CDATA[General]]></category>
			<category><![CDATA[Logs]]></category>
			<guid isPermaLink="true">http://blogs.manageengine.com/eventloganalyzer/2009/07/09/security-vs-operational-efficiency-striking-the-balance-with-productive-tools</guid>
			<pubDate>Thu, 9 Jul 2009 05:21:56 -0700</pubDate>
		</item>

		<item>
			<title>Best Practices in Log Management for Effective Compliance</title>
			<link>http://blogs.manageengine.com/eventloganalyzer/2009/06/18/best-practices-in-log-management-for-effective-compliance</link>
			<dc:creator>Pooja Sengupta</dc:creator>
			<description><![CDATA[<p style="margin-bottom: 0in;" align="justify">Compliance is vital for
any enterprise not merely to adhere to various regulatory/industry
frameworks but also to mitigate the risks attached to corporate IT
assets. Enterprises failing to comply not only face penalties from
the regulatory bodies but also risk losing respectability and trust.
However, in recent times many enterprises fail to remain fully
compliant at all times which has led to many security breaches. Case
in point, the recent Heartland breach highlighted the fact that
staying compliant is a full-time process and just staying within the
boundaries of a given regulatory framework is not sufficient to
secure your network(s). Enterprises therefore need to look beyond the
applicable frameworks to achieve compliance, and one important way is
to analyze and manage system, application and event logs to prevent
such huge incidents.</p>
<p style="margin-bottom: 0in;" align="justify">Log management for
Compliance requirements is an increasingly vital process for
enterprises across verticals. There are several implications to
having an ineffective log management process, both tangible and
intangible.</p>
<p style="margin-bottom: 0in;" align="justify">Enterprises that analyze
their log data efficiently can easily recognize the value and impact
on their IT and overall operations. The insight gained by log
analysis and reporting can help enterprises determine their existing
security implementation, cut down on costs on extensive regulatory
audits and recovery measures, if any. Up to date log data analysis
provides insight into the health and accessibility of network(s),
system and applications.</p>
<p style="margin-bottom: 0in;" align="justify">A strong log management
solution that handles voluminous and variety of logs is a necessary
tool for enterprises to maintain the integrity of all data.</p>
<p style="margin-bottom: 0in;" align="justify">Let’s look at a
checklist to ensure log management is applied effectively to ensure
compliance.</p>
<h1 class="western" align="justify">Do’s</h1>
<ol><li><p style="margin-bottom: 0in;" align="justify">Make Log management
	a daily routine and not just to satisfy compliance requirements</p>
</li></ol>
<p style="margin-left: 1in; margin-bottom: 0in;" align="justify">If log
management is not done only for the sake of meeting regulatory
requirements then we can cover our bases much more effectively. It
will take care of any overlapping frameworks and reduce the time to
meet all regulatory requirements. This will also cover any condition
that is overlooked in the impression that another regulatory
requirement covers it. Reports and alerts ensure that the security
threat posed is brought to your attention, including those beyond the
scope of regulatory compliance.</p>
<p style="margin-left: 1in; margin-bottom: 0in;" align="justify"><br>
</p>
<ol start="2"><li><p style="margin-bottom: 0in;" align="justify">Ensure alerts are
	set up as per the requirements of the enterprise 
	</p>
</li></ol>
<p style="margin-left: 1in; margin-bottom: 0in;" align="justify">Ensure
all alerts are set up correctly and for the specific requirements of
the enterprise and not just to meet compliance requirements. If any
critical data is suspected to have been accessed by an unauthorized
user it must be alerted instead of ignoring it if it doesn’t meet a
specific regulatory requirement. The alert set up must be reviewed
and reassessed periodically.</p>
<p style="margin-left: 1in; margin-bottom: 0in;" align="justify"><br>
</p>
<ol start="3"><li><p style="margin-bottom: 0in;" align="justify">Review reports
	regularly to identify any gaps in the set up and regulatory
	requirements.</p>
</li></ol>
<p style="margin-left: 1in; margin-bottom: 0in;" align="justify">All
reports must be checked not just for the expected data but also for
any anomalies in them. Reports must be maintained also for what
doesn’t meet the requirements and reviewed frequently.</p>
<p style="margin-left: 1in; margin-bottom: 0in;" align="justify"><br>
</p>
<ol start="4"><li><p style="margin-bottom: 0in;" align="justify">Conduct periodic
	tests to determine the effectiveness of the set up.</p>
</li></ol>
<p style="margin-left: 1in; margin-bottom: 0in;" align="justify">The
network must be tested for effectiveness and efficiency in managing
and analyzing logs in order to ensure that compliance requirements
are met appropriately. A robust log management solution is a vital
key towards staying compliant. The test must also be highlighted and
validated by the system.</p>
<p style="margin-left: 1in; margin-bottom: 0in;" align="justify"><br>
</p>
<ol start="5"><li><p style="margin-bottom: 0in;" align="justify">Have a
	representative from the legal department to check if all regulatory
	requirements are understood and met by the IT department.</p>
</li></ol>
<p style="margin-left: 1in; margin-bottom: 0in;" align="justify">Not all
regulatory requirements are easy to comprehend and hence might be
misunderstood by those defining the IT compliance requirements. This
is a pitfall that must be avoided hence all legal aspects must be
simplified.</p>
<p style="margin-left: 1in; margin-bottom: 0in;" align="justify"><br>
</p>
<ol start="6"><li><p style="margin-bottom: 0in;" align="justify">Have a consistent
	approach to managing and analyzing the logs.</p>
</li></ol>
<p style="margin-left: 1in; margin-bottom: 0in;" align="justify">Make
sure there are defined set of rules on how logs must be managed and
analyzed. This must be dependent on the enterprise and not on the
authorized personnel. If any change in authority takes place the set
of rules for log handling mustn’t be changed as this can lead to
loss of log data.</p>
<p style="margin-left: 1in; margin-bottom: 0in;" align="justify"><br>
</p>
<ol start="7"><li><p style="margin-bottom: 0in;" align="justify">Check for
	unauthorized programs installed by users within the network.</p>
</li></ol>
<p style="margin-left: 1in; margin-bottom: 0in;" align="justify">Most
breaches are caused due to malicious code planted in the network
through unauthorized programs. Users are mostly unaware of the
potential threat in installing seemingly harmless programs. A log
management solution can help detect such unauthorized programs and
alert the administrator before any harm is done.</p>
<h1 class="western" align="justify">Don’ts</h1>
<ol><li><p style="margin-bottom: 0in;" align="justify">Give access to
	unauthorized users to view, edit and delete any information.</p>
</li></ol>
<p style="margin-left: 1in; margin-bottom: 0in;" align="justify">Access
to the network must be strictly monitored and only given to
authorized members. Data should be classified appropriately and
access to them regulated and monitored. All unauthorized access must
be alerted promptly by the log management solution.</p>
<p style="margin-left: 1in; margin-bottom: 0in;" align="justify"><br>
</p>
<ol start="2"><li><p style="margin-bottom: 0in;" align="justify">Provision any
	Team/group access to any critical data.</p>
</li></ol>
<p style="margin-left: 1in; margin-bottom: 0in;" align="justify">No
authorization must be provided on a team/group level as this is a
greater exposure to risks and provide room for human error. Any
changes made on one-on-one level will be lost if not communicated on
team/group level.</p>
<p style="margin-left: 1in; margin-bottom: 0in;" align="justify"><br>
</p>
<ol start="3"><li><p style="margin-bottom: 0in;" align="justify">Keep unnecessary
	ports open in the network.</p>
</li></ol>
<p style="margin-left: 1in; margin-bottom: 0in;" align="justify">All
redundant ports must be closed in the network(s) in order to protect
it from any malicious attack. Ports must be periodically reviewed to
ensure only those required are accessible.</p>
<p style="margin-left: 1in; margin-bottom: 0in;" align="justify"><br>
</p>
<ol start="4"><li><p style="margin-bottom: 0in;" align="justify">Run unused services
	in vital servers.</p>
</li></ol>
<p style="margin-left: 1in; margin-bottom: 0in;" align="justify">In
order to keep the network(s) efficient and easy to manage all unused
services must be stopped to avoid any conflict with essential
services. Any redundant service poses a risk in interfering with the
operation of critical resources, which will lead to failure of
required processes.</p>
<p style="margin-bottom: 0in;" align="justify">This isn’t a
comprehensive checklist of course but if you don’t have one, this
might be a good place to start. Each enterprise needs to get started
with log management with their customized set of checklists to ensure
the enterprise IT network(s) is optimally secured. Merely being
compliant isn’t enough; it also requires staying more vigilant and
having stringent security measures in place.</p><p style="margin-bottom: 0in;" align="justify"><span><a href="http://www.twitter.com/pooja4logs"><img src="http://blogs.manageengine.com/image/501000000056211/twitteranime2.gif" style=""></a></span><br></p><p></p>]]></description>
			<category><![CDATA[General]]></category>
			<category><![CDATA[Compliance]]></category>
			<category><![CDATA[Logs]]></category>
			<guid isPermaLink="true">http://blogs.manageengine.com/eventloganalyzer/2009/06/18/best-practices-in-log-management-for-effective-compliance</guid>
			<pubDate>Thu, 18 Jun 2009 04:43:39 -0700</pubDate>
		</item>

		<item>
			<title>ManageEngine EventLog Analyzer Voted First Runner-Up in WindowSecurity.com Readers' Choice Awards</title>
			<link>http://blogs.manageengine.com/eventloganalyzer/2009/05/14/manageengine-eventlog-analyzer-voted-first-runner-up-in-windowsecuritycom-readers-choice-awards</link>
			<dc:creator>Ragavan S</dc:creator>
			<description><![CDATA[<p><span class="Apple-style-span" style="text-align: left;font-family: Verdana;color: #222222"><a href="http://www.manageengine.com/products/eventlog/index.html">ManageEngine EventLog Analyzer</a><span class="Apple-converted-space"> </span>was selected first runner-up in the Event Log Monitoring category of the WindowSecurity.com Readers' Choice Awards.<span class="Apple-converted-space"> </span></span></p>
<p><span class="Apple-style-span" style="text-align: left;font-family: Verdana;color: #222222"><span class="Apple-converted-space"><a href="http://www.windowsecurity.com/news/WindowSecurity-Readers-Choice-Award-Event-Log-Monitoring-EventSentry-Feb09.html">http://www.windowsecurity.com/news/WindowSecurity-Readers-Choice-Award-Event-Log-Monitoring-EventSentry-Feb09.html</a></span></span></p>
<p><span class="Apple-style-span" style="text-align: left;font-family: Verdana;color: #222222"><span class="Apple-converted-space">PR for the Award:</span></span></p>
<p><a href="http://www.marketwire.com/press-release/Manageengine-985914.html">http://www.marketwire.com/press-release/Manageengine-985914.html</a></p>
<p><a href="http://linux.sys-con.com/node/952966">http://linux.sys-con.com/node/952966</a></p>
<p>Website: <a href="http://www.eventloganalyzer.com">http://www.eventloganalyzer.com</a></p>
<p>Follow us on Twitter <a href="http://twitter.com/LogAnalyzer">http://twitter.com/LogAnalyzer</a></p>
]]></description>
			<category><![CDATA[All]]></category>
			<guid isPermaLink="true">http://blogs.manageengine.com/eventloganalyzer/2009/05/14/manageengine-eventlog-analyzer-voted-first-runner-up-in-windowsecuritycom-readers-choice-awards</guid>
			<pubDate>Thu, 14 May 2009 23:35:02 -0700</pubDate>
		</item>

		<item>
			<title>Automate Compliance Log Management</title>
			<link>http://blogs.manageengine.com/eventloganalyzer/2009/02/20/automate-compliance-log-management</link>
			<dc:creator>Pooja Sengupta</dc:creator>
			<description><![CDATA[Those who deal with log auditing and reporting for compliance requirements know they have a critical task to process. Watch this video to understand the various regulatory compliance requirements for log management. We talk about PCI, SOX, HIPAA and GLBA requirements and how EventLog Analyzer can help in achieving those compliance goals.
<p><object height="375" width="500"><embed type="application/x-shockwave-flash" src="http://manageengine.adventnet.com/products/eventlog/ela-automates-compliance/ela-automates-compliance_controller.swf" height="375" width="500" allowscriptaccess="never"></embed></object><a href="http://manageengine.adventnet.com/products/eventlog/ela-automates-compliance/ela-automates-compliance_controller.swf"></a></p>
<span><a href="http://www.twitter.com/pooja4logs"><img src="http://blogs.manageengine.com/image/501000000056217/twitteranime2.gif" style=""></a></span>

]]></description>
			<category><![CDATA[All]]></category>
			<guid isPermaLink="true">http://blogs.manageengine.com/eventloganalyzer/2009/02/20/automate-compliance-log-management</guid>
			<pubDate>Fri, 20 Feb 2009 22:13:22 -0800</pubDate>
		</item>

		<item>
			<title>Windows Vista and 2008 server Events</title>
			<link>http://blogs.manageengine.com/eventloganalyzer/2008/12/08/windows-vista-and-2008-server-events</link>
			<dc:creator>karthik</dc:creator>
			<description><![CDATA[<p>Windows 2008 servers have been around for about 10 months now and chances are they have made their way into your IT department. Many among you would be aware of the changes that have been introduced in Vista and Win2k8 servers. There has been a number of changes in the logging infrastructure, the most interesting of the lot is the renumbering of security event ids.</p>
<p>The event ids of Vista and 2008 servers compared to its predecessors generally follow a '<em><strong>offset by 4096</strong></em>' rule, i.e the good old logon event represented by id 528 is now 4624(4096+528) and so on. However, this offset rule is not a universal change and there are a few gotchas that surface here and there. For example, logon failures in pre-vista systems were represented by a multitude of event ids ranging from 529 to 537(each indicating a specific reason for the failure), this has now been unified to a single event, namely 4625 and a new field 'Failure Reason' has been added to the message under the category 'Failure Information' highlighting the reason. Another example of this is the 'Audit Log Cleared' event. This event is logged with the id 517 in pre-vista machines but is now changed to 1102 with the source being 'EventLog'(this is another change that skipped mention, the 'Source' of the Security log which till now is 'Security' has been refined to a more meaningful field, the security audit events take the source 'Microsoft Windows Security Auditing', while as mentioned audit logs cleared is logged with source 'Eventlog'.)</p>
<p>The following KB article is a handy reference describing the various security and audit based events in Vista and 2008 servers.<br />
<a href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;947226">http://support.microsoft.com/default.aspx?scid=kb;EN-US;947226</a></p>
<p>Scrolling down to the "Notes" section at the bottom of the article, you will find information about a useful command line utility 'wevtutil', which when used in the form mentioned in the article(wevtutil gp Microsoft-Windows-Security-Auditing /ge /gm:true) fetches a detailed description of every security based event id.</p>
<p>That just about wraps up this post, oh. . and just one more thing. We have set out a small initiative to get <em><strong>you</strong></em>, the real users of the product, tell us what you want from the product over <a href="http://roadmap.manageengine.com/index.php?category=EventLogAnanlyzer">here</a>. The idea behind this is to listen to what improvements you want and if enough users agree, we will work on it on a priority basis. The whole thing is very much in a nebulous state with no entries yet, we encourage you to use this facility to tell us what you would like.</p>
<p>Until next time, ciao.</p>
]]></description>
			<category><![CDATA[All]]></category>
			<guid isPermaLink="true">http://blogs.manageengine.com/eventloganalyzer/2008/12/08/windows-vista-and-2008-server-events</guid>
			<pubDate>Mon, 8 Dec 2008 21:15:39 -0800</pubDate>
		</item>

		<item>
			<title>Relax! It is Easy to Abide by the Government Act for Network Security!!</title>
			<link>http://blogs.manageengine.com/eventloganalyzer/2008/11/02/relax-it-is-easy-to-abide-by-the-government-act-for-network-security</link>
			<dc:creator>Ragavan S</dc:creator>
			<description><![CDATA[<p>When it is a matter of network security, be pro-active. Do not wait for compliance regulation or statutory government legislation.</p>
<p>But, once a regulatory body of your domain formulates compliance acts, you should ensure that your network is secured and compliant with the regulatory act. This will also instill confidence in your customers that you are following standard practices to keep your network secured.</p>
<p>At the next level, if a national government promulgates a law to counter the computer related offenses and if you operate in that country, you have to abide by the act. Failing which you will attract penal action and punishment.</p>
<p>One such example is '<span style="font-family: TimesNewRomanPSMT">Computer Crime Act B.E 2550 (2007)' of Thailand government.</span></p>
<p><span style="font-family: TimesNewRomanPSMT">Enterprises with computer networks and service providers should scout for a Security Information Management (SIM) solution which fulfills the requirements of the government act.</span></p>
<p>The SIM solution application should be,</p>
<ul>
<li>
<div>easy to use</div>
</li>
<li>
<div>should be able to install on any platform </div>
</li>
<li>
<div>
<div>access the application from anywhere (should we say web-based)</div>
</div>
</li>
<li>
<div>should require minimum manual intervention to operate</div>
</li>
<li>
<div>collect the security information (logs) from a central location</div>
</li>
<li>
<div>agent should not be required </div>
</li>
<li>
<div>should collect information from heterogeneous devices</div>
</li>
<li>analyse, normalise, and aggregate the log information</li>
<li>provide multi-format, canned, customisable, scheduled, and distributable reports</li>
<li>generate alerts for anomalous and specific log information</li>
<li>notify the alerts by Email or other means</li>
<li>flexible archiving of log information to suit the requirements of government act</li>
<li>importing the log information from archive or any other system which is not monitored by the application</li>
<li>analysing and generating reports for imported log information</li>
<li>exhaustive search feature to cater for forensic analysis requirements of government act</li>
<li>above all, it should not pinch your pocket</li>
</ul>
<p>Wonder whether some such SIM solution is available? Give <span style="color: #009900"><strong>Manage</strong></span>Engine <a href="http://www.eventloganalyzer.com/" target="_blank">EventLog Analyzer</a> a try.</p>
]]></description>
			<category><![CDATA[All]]></category>
			<guid isPermaLink="true">http://blogs.manageengine.com/eventloganalyzer/2008/11/02/relax-it-is-easy-to-abide-by-the-government-act-for-network-security</guid>
			<pubDate>Sun, 2 Nov 2008 22:17:31 -0800</pubDate>
		</item>

		<item>
			<title>Have some fun with the toonz</title>
			<link>http://blogs.manageengine.com/eventloganalyzer/2008/09/23/have-some-fun-with-the-toonz</link>
			<dc:creator>Ragavan S</dc:creator>
			<description><![CDATA[<p><a href="http://blogs.manageengine.com/eventloganalyzer/files/2008/09/cool-cartoon-366743.png"></a></p>
<div class="mceTemp mceIEcenter" style="text-align: center"><a href="/image/501000000022940/cool-cartoon-3667432.png"><img class="aligncenter size-full wp-image-301" src="/image/501000000022940/cool-cartoon-3667432.png" alt="" width="500" height="303" /></a></div>
<div class="mceTemp mceIEcenter" style="text-align: left">Want to know more about Privileged User Threat? Refer <a title="EventLog Analyzer - PUMA" href="http://manageengine.adventnet.com/products/eventlog/index.html" target="_blank">EventLog Analyzer</a>.</div>
]]></description>
			<category><![CDATA[All]]></category>
			<guid isPermaLink="true">http://blogs.manageengine.com/eventloganalyzer/2008/09/23/have-some-fun-with-the-toonz</guid>
			<pubDate>Tue, 23 Sep 2008 23:07:29 -0700</pubDate>
		</item>

		<item>
			<title>Road to better Enterprise IT Security leads to - ME Euro Roadshow 2008</title>
			<link>http://blogs.manageengine.com/eventloganalyzer/2008/08/29/road-to-better-enterprise-it-security-leads-to-me-euro-roadshow-2008</link>
			<dc:creator>Ragavan S</dc:creator>
			<description><![CDATA[<p>Yes!</p>
<p>AdventNet ManageEngine is hosting Roadshows in countries across the European Union.</p>
<p>If security of your enterprise IT infrastructure is your concern, then you must visit ME Euro Roadshow 2008.</p>
<p>We are available in your town. Feel free to seek any information about <a href="http://manageengine.adventnet.com/products/eventlog/" target="_blank">EventLog Analyzer</a>.  Join us at the Roadshow in your country, <a title="ME EURO Roadshow Register" href="http://manageengine.adventnet.com/euroroadshow/registration.html" target="_blank">register here</a> </p>
<p>Check complete details about the Roadshow, visit the link: <a href="http://manageengine.adventnet.com/euroroadshow/">http://manageengine.adventnet.com/euroroadshow/</a></p>
]]></description>
			<category><![CDATA[General]]></category>
			<guid isPermaLink="true">http://blogs.manageengine.com/eventloganalyzer/2008/08/29/road-to-better-enterprise-it-security-leads-to-me-euro-roadshow-2008</guid>
			<pubDate>Fri, 29 Aug 2008 01:26:09 -0700</pubDate>
		</item>
	</channel>
</rss>
