Jump to content

Security Information & Event Management (SIEM)

Enhance Network Security and Compliance with Comprehensive Log Management

Minimizing Security Vulnerabilities

With the complexity and interdependence of networks and systems, security vulnerabilities have become harder to detect and control. External security threats can occur when malicious agents or groups launch denial of service or intrusion attempts via wired or wireless access or through malware propagation.

Internal security threats are even more commonplace, with unauthorized users gaining access to sensitive information and devices. In fact, simple mistakes like leaving a logged on application screen can become an easy entry point for rogue users to make unauthorized changes, compromise data protection and endanger network security.

Privacy and Regulatory Compliance

At the same time, privacy and regulatory rules are becoming more stringent and organizations have to put in place adequate security measures to prove compliance, perform forensics and support law enforcement investigations - if in fact a breach does happen.

The WhatsUp Gold Solution

The WhatsUp Log Management solution provides comprehensive support for security information and event management across your network, systems and application infrastructure. It collects, analyzes, stores, filters and reports on volumes of log data generated by Windows, Unix and Linux systems or from routers, switches, firewall and IPS/IDS devices.

An Automated & Intelligent Platform

Since manual intervention and identification of security vulnerabilities and compliance breaches are impossible, WhatsUp Log Management provides the automation and intelligence to undertake these tasks. Managers and compliance officers know their log record database can be accessed and analyzed to either prevent a breach in near real-time or used to define policies and processes that could avoid future incidents.

The SEIM Management Challenge and the WhatsUp Gold Solution:

  • Pre-empt and thwart security incidents as they happen. In near real-time, the WhatsUp Event Alarm system continuously monitors and analyzes Windows Event and Syslog records for threat patterns and alerts administrators as required.
  • Deliver operational support for troubleshooting and compliance assurance. Rapid visualization and filtering of raw log data is crucial for a fast operational response and triage. WhatsUp Event Rover lets you review log data onthe- fly and also data mine Windows event and Syslog files for operations and compliance support.
  • Establish security and log management policies. To manage across Windows and Syslog versions, WhatsUp Event Analyst delivers normalized reporting and benchmarking, providing a common understanding of security information and policy definition.
  • Log archival and compliance assessment. Infrastructure components constantly generate log messages reporting on changes and activity – whether routine or malicious. WhatsUp Event Archiver collects and stores Windows event and Syslog files to support later forensic analysis and compliance audits.