<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-664210819190911909</id><updated>2011-07-31T03:58:31.240+02:00</updated><category term='Audit Log'/><category term='Analyze'/><category term='SOX'/><category term='Collect'/><category term='Reports'/><category term='PCI'/><category term='Integration'/><category term='Compliance'/><category term='Cloud'/><title type='text'>LogInspect</title><subtitle type='html'>This site is dedicated to transfer knowledge about SIEM Log Management and specifically tol the solution called LogInspect</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://loginspect.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/664210819190911909/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://loginspect.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>ImmuneSecurity</name><uri>http://www.blogger.com/profile/09754649611449803870</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>3</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-664210819190911909.post-4640239708319541215</id><published>2010-10-14T22:24:00.004+02:00</published><updated>2010-10-14T22:48:43.985+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cloud'/><category scheme='http://www.blogger.com/atom/ns#' term='Integration'/><title type='text'>Cloud based Log Management - Good or bad?</title><content type='html'>Are&amp;nbsp;cloud based application services&amp;nbsp;something that would suit well for a SIEM solution as well?&lt;br /&gt;&lt;br /&gt;This is not an easy question to answer, since there are many things to consider when going towards a cloud based solution.&lt;br /&gt;&lt;br /&gt;IT Managers are aware that Log Management is not an easy task, but taking the extra step and handing over sensible data to a 3rd party and on top of that, having to rely on that the data is available when it is needed.&lt;br /&gt;It is almost as difficult a decision as the first time you let your oldest&amp;nbsp;daughter sleep over at a friends house after a party.&lt;br /&gt;&lt;br /&gt;I guess it all comes back to the reasons why you need a Log Management tool and&amp;nbsp;some common&amp;nbsp;drivers are:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;IT Operations needs it for rootcause analysis and problem resolution&lt;/li&gt;&lt;li&gt;Security uses the information to monitor events and suspicious user behavior&lt;/li&gt;&lt;li&gt;Audit and Compliance officers are worried about sensible data and who has access to it.&lt;/li&gt;&lt;/ul&gt;Apart from Audit and Compliance,&amp;nbsp;most other use cases need log data to be immediately available for event processing and alerting purposes. So I guess it comes back to service that the vendor is offering and some of the things that should be checked are:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Application availability&lt;/li&gt;&lt;li&gt;Timeliness of log data storage and analysis&lt;/li&gt;&lt;li&gt;Device support&lt;/li&gt;&lt;li&gt;How long is log data stored and searchable&lt;/li&gt;&lt;li&gt;Backup and redundancy&lt;/li&gt;&lt;/ul&gt;Most of the vendors of cloud based solutions all have good explanations to above mentioned points, but by choosing such a solution, it is very likely that after the first internal hype, it's not going to be used actively and only seen as a place to store the log data and possibly for compliance reporting.&lt;br /&gt;Therefor the money spend on implementing a cloud based solution, is more or less wasted and the time spend setting it up, could be used much better in other ways.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Integration to other applications&lt;/strong&gt;&lt;br /&gt;If you plan on integrating a solution in-house, you get the benefit of integrating your solution with your other management tools and this assures that the Log Management solution is very much an integrated part of your day-to-day operations, whether it's operation, security or compliance related.&lt;br /&gt;The system can&amp;nbsp;generate events that can help you with the following:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Triggers scripts like shutting down a firewall port&lt;/li&gt;&lt;li&gt;Executes applications&lt;/li&gt;&lt;li&gt;Sending alerts via text messages&lt;/li&gt;&lt;li&gt;Integrating into help-desk systems like Remedy&lt;/li&gt;&lt;/ul&gt;All these functions are just samples of how to get the most out of your Log Management system, by integrating seamlessly into,&amp;nbsp;as well as enhancing, your existing application infrastructure.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Summary&lt;/strong&gt;&lt;br /&gt;So if you need Log Management for storage and occasional searches, a cloud based solution is the right fit for you.&lt;br /&gt;But if you want to prevent your solution from becomming a stand-alone application,&amp;nbsp;and you want to use the valuable&amp;nbsp;information contained in logs, to improve your day-to-day operations, you are better off with&amp;nbsp;an in-house solution. For now, you definitely get the most out of every dollar you spend.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/664210819190911909-4640239708319541215?l=loginspect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://loginspect.blogspot.com/feeds/4640239708319541215/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://loginspect.blogspot.com/2010/10/cloud-based-log-management-good-or-bad.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/664210819190911909/posts/default/4640239708319541215'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/664210819190911909/posts/default/4640239708319541215'/><link rel='alternate' type='text/html' href='http://loginspect.blogspot.com/2010/10/cloud-based-log-management-good-or-bad.html' title='Cloud based Log Management - Good or bad?'/><author><name>LogInspect</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-664210819190911909.post-3475275881914243024</id><published>2010-08-16T22:13:00.001+02:00</published><updated>2010-08-17T13:26:26.179+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Audit Log'/><category scheme='http://www.blogger.com/atom/ns#' term='SOX'/><category scheme='http://www.blogger.com/atom/ns#' term='Reports'/><category scheme='http://www.blogger.com/atom/ns#' term='Compliance'/><category scheme='http://www.blogger.com/atom/ns#' term='PCI'/><title type='text'>Log Management and Compliance</title><content type='html'>&lt;span style="font-family: Verdana,sans-serif;"&gt;LogInspect can help you achieve a complete insight to your network, and help meeting common regulations such as PCI, Sarbanes Oxley, HIPAA, Basel-II, ISO-17799 (auditing and monitoring) and ISO27001 which includes DS-484:2005. The LogInspect provides prebuilt templates for most common use-cases like compliance and security reports. But reports can also be custom made with the modular report engine so it matches your needs.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;b&gt;Reports on Asset Security Modifications.&lt;/b&gt; Security changes to a system asset is registered in a "Security Modification" category.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;b&gt;Reports on User Authentication.&lt;/b&gt; User authentication are stored for reporting in administrator successful and failed attemps, plus user successful and failed attempts.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;b&gt;Reports on Security Incidents.&lt;/b&gt; Security Incidents and system errors are automatically detected and reported by the LogInspect intelligence.&lt;/span&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;/span&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;Besides presentation the findings in easily to read reports we also meeting other requirements put forward by the regulations such as.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;b&gt;Integrity of Logs.&lt;/b&gt; Log data collected are stored in a secure archive which protects against data modifications and audit logs disappears (with checksums and double timestamps).&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;b&gt;Access to Original Log Data.&lt;/b&gt; The original log format is accessible for backup, forensic usage and statistical usage. This gives a big flexibility when integrating with third party vendors or investigators.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;b&gt;Asset Owners.&lt;/b&gt; Each asset defined can have a primary owner and a list of secondaries. This makes the process of incident respond and incident management more smooth since there can be set a default assigned person (or group).&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;b&gt;Role Based Access.&lt;/b&gt; LogInspect has a very complex Role Based Access model which can be used if needed. Every view can be defined whether they are allowed to be presented or not for a user and each object can have its own settings too. A good use-case example of this is; to let a user view (but not modifiy) all pages, and only present the systems which he/she is responsible for.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;b&gt;Audit Logs.&lt;/b&gt; Every authentication attempt and user action made which results in a modification is logged in an audit log. This audit log can be used to track changes to discover errors based on configuration, who made the changes and from where.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/664210819190911909-3475275881914243024?l=loginspect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://loginspect.blogspot.com/feeds/3475275881914243024/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://loginspect.blogspot.com/2010/08/log-management-and-compliance.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/664210819190911909/posts/default/3475275881914243024'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/664210819190911909/posts/default/3475275881914243024'/><link rel='alternate' type='text/html' href='http://loginspect.blogspot.com/2010/08/log-management-and-compliance.html' title='Log Management and Compliance'/><author><name>LogInspect</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-664210819190911909.post-3166541543628150156</id><published>2010-08-16T21:58:00.001+02:00</published><updated>2010-08-17T13:27:27.830+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Collect'/><category scheme='http://www.blogger.com/atom/ns#' term='Analyze'/><title type='text'>Automated Log Management</title><content type='html'>&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;b&gt;COLLECT – STORE – ANALYZE – REPORT&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;Collection of logs is demanded by regulatory or security requirements. Log data is collected from any number of devices on a network and is created in the millions every day resulting in a staggering volume that in itself is a huge task to manage. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;Secure storing of the massive Log data is imperative for IT controls and compliance. The LogInspect architecture ensures that any IT environment, whether local or distributed worldwide, can scale to fit even the most demanding IT infrastructures. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;Analysis remains the most sophisticated part of LogInspect. Different devices generate logs in a distinct, inconsistent and often cryptic format that is difficult to analyze without in-depth system specific expertise. Also, many of the conditions that indicate issues can only be detected when logs are correlated or associated with logs happening on other systems and devices. If caught in time, these signs can alert personnel to take necessary actions before security is compromised.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;LogInspect analysis is done in real-time for immediate insight into unusual and suspicious user/network activity - a task that is impossible to do manually in even midsized companies.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: Verdana,sans-serif;"&gt;Once a given task is defined the best management tool for control is reporting. LogInspect include a powerful report generator that makes it easy to define and schedule relevant reports based on standard compliance or fully customized requirements.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/664210819190911909-3166541543628150156?l=loginspect.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://loginspect.blogspot.com/feeds/3166541543628150156/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://loginspect.blogspot.com/2010/08/automated-log-management.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/664210819190911909/posts/default/3166541543628150156'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/664210819190911909/posts/default/3166541543628150156'/><link rel='alternate' type='text/html' href='http://loginspect.blogspot.com/2010/08/automated-log-management.html' title='Automated Log Management'/><author><name>LogInspect</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
