Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Security Basics
log analyser May 28 2009 11:25PM
sec nd-f com (7 replies)
Re: log analyser Jun 11 2009 03:38AM
TT-SEC (secfoc tigerteam net) (1 replies)

I apologize for replying to a late thread. I debated as to whether I
should, but given the recent tests and research that I have been
conducting for the US Gov I felt compelled to share my findings. My
research has uncovered a product, previously developed by the US
Government (as a database), but now licensed and enhanced for commercial
use through a company called Nitro Security. My benchmarks, which I was
highly skeptical of initially when presented as vendor claims, do show
their back end technology to truly be between 500-1000% faster then my
standard Oracle and MySQL deployments (~80k inserts per second) that I
oversee.

I've had Oracle professional services in house to attempt to tweak their
database to better fit my needs as a backend for ArcSight with no avail
as well. What I've seen is that the feature set that Nitro provides
compared to ArcSight in the high level heuristic and reporting world
(which is rarely all that accurate in enterprise products anyway) to
provide data analysis of literally billions of events and flows in a
matter of seconds and minutes. The anomaly detection and correlated
baselines are something that I haven't seen demonstrated in any other
product. For operational purposes, I fully expect to replace ArcSight
soon. Many people are tired of the endless professional services and
incredibly expensive annual licensing fees.I don't want to sound like a
shill for this company in any way, but simply want to report the unique
performance and results that I have seen per my own testing. The
database foundation (which they also utilize custom solid state drives
in some applications) enables functionality like I've never seen before.
I really can't pass along to many details about my testing is it has
occurred under contract, but I felt compelled to pass along the fact
that it has resulted in some highly unique results. Thanks for the time.

Best Regards,
Jamie Tyler, CISSP, MCSE

sec (at) nd-f (dot) com [email concealed] wrote:
> Hi,
>
> can someone of you recommend a good enterprise log analyser solution? i have to collect, corrolate and analyse about 1200 windows machines and 200 linux boxes. i want to do this in real-time, trigger actions (like email notification), make sense out of e.g. ten failed login attempts following the one successful etc.
>
> any hint would be helpful
> thanks
> andy
>
> ------------------------------------------------------------------------

> This list is sponsored by: InfoSec Institute
>
> Need to pass the CISSP? InfoSec Institute's CISSP Boot Camp in both Instructor-Led and Online formats is the most concentrated exam prep available. Comprehensive course materials and an expert instructor means you pass the exam. Gain a laser like insight into what is covered on the exam, with zero fluff!
>
> http://www.infosecinstitute.com/courses/cissp_bootcamp_training.html
> ------------------------------------------------------------------------

>
>

------------------------------------------------------------------------

This list is sponsored by: InfoSec Institute

Need to pass the CISSP? InfoSec Institute's CISSP Boot Camp in both Instructor-Led and Online formats is the most concentrated exam prep available. Comprehensive course materials and an expert instructor means you pass the exam. Gain a laser like insight into what is covered on the exam, with zero fluff!

http://www.infosecinstitute.com/courses/cissp_bootcamp_training.html
------------------------------------------------------------------------

[ reply ]
Re: log analyser Jun 12 2009 03:32PM
Richard Thomas (austindad gmail com) (1 replies)
Multi thread Jul 02 2009 05:42PM
Antão Miguel Chantre (chantre sisp cv) (1 replies)
Re: Multi thread Jul 08 2009 08:46PM
Suramya Tomar (security suramya com)
Re: log analyser Jun 02 2009 02:24AM
aditya mukadam (aditya mukadam gmail com) (3 replies)
RE: log analyser Jun 06 2009 02:50PM
Ramki B Ramakrishnan (bramkie gmail com)
RE: log analyser Jun 04 2009 05:27AM
Tariq Naik (Tariq_Naik symantec com)
RE: log analyser Jun 02 2009 06:03PM
Amardeep Singh (Amardeep_Singh symantec com)
RE: log analyser Jun 01 2009 07:30PM
John Lightfoot (jlightfoot gmail com)
Re: log analyser Jun 01 2009 05:22PM
Jared Curtis (jared w00ttech com)
Re: log analyser Jun 01 2009 04:58PM
giuseppe fuggiano gmail com
Re: log analyser Jun 01 2009 04:22PM
Abilash Praveen (abilash praveen gmail com)
RE: log analyser Jun 01 2009 04:05PM
Hindley Nick (Nick Hindley hfbp co uk) (1 replies)
RE: log analyser Jun 01 2009 05:17PM
Todd Neal (ToddNeal tnwinc com)







 

Privacy Statement
Copyright 2009, SecurityFocus