LogAnalysis
[logs] SIM solution - Objectives ? May 24 2007 05:52AM
saudi sans (saudisans gmail com) (3 replies)
Re: [logs] SIM solution - Objectives ? May 25 2007 08:12AM
Tom Le (dottom gmail com)
Re: [logs] SIM solution - Objectives ? May 24 2007 01:43PM
Paul Melson (pmelson gmail com)
Re: [logs] SIM solution - Objectives ? May 24 2007 12:58PM
Ron Gula (rgula tenablesecurity com) (1 replies)
Hi Saudi,

The real question is what constitutes a high alert for your network.
This is the biggest differentiator I've seen in deployments of our
logging products or other log/event managers out there.

If a high alert is nothing more than calling you if a certain Snort
event occurs, that is pretty simplistic and I don't really see a need to
be called within 15 or 30 minutes since this should be automated.

However, if your "high" alert is something more serious like a
successful compromise, a PCI/compliance usage violation or just that the
main firewall went down, I could see putting these into specific SLA
obligations being quite difficult to nail down. It could take more CPU
computation to arrive at a conclusion that a high quality alert occurred
within a specific policy, but most SIM/log-analyzers can do this sort of
thing today.

Separating High and Medium events based on alert time seems really
artificial to me. If your MSP is using automation to get an alert, I
doubt the Medium alerts take longer to compute than the High alerts.

(I haven't posted much here but Tenable does offer log aggregation,
normalization and correlation tools for netflow, syslog, firewalls, .etc)

Ron Gula, CTO
Tenable Network Security
http://www.tenablesecurity.com

saudi sans wrote:
> Hi,
>
> We have just started using a leading SIM for monitoring logs. It works
> well.
>
> The SIM management is outsourced. We have about 150 servers and 10
> security devices.
>
> We have SLAs that if a High alert comes vendor should inform us within
> 15 minutes , for medium alert it is 30 minutes .....etc.
>
> Are corporates [who have some level of maturity in this space] using
> SIM solutions to do real time response or are we using it for weekly
> reports and then doing trend analysis ?
>
> Does it make sense to receive High alerts and take a 15 minute
> response when a login failure happens on a few servers.?
>
> This question is NOT related to the SIM product capabilities but
> process to be followed and what goals we should set to achieve with
> SIM
> _______________________________________________
> LogAnalysis mailing list
> LogAnalysis (at) loganalysis (dot) org [email concealed]
> http://www.loganalysis.org/mailman/listinfo/loganalysis
>

_______________________________________________
LogAnalysis mailing list
LogAnalysis (at) loganalysis (dot) org [email concealed]
http://www.loganalysis.org/mailman/listinfo/loganalysis

[ reply ]
Re: [logs] SIM solution - Objectives ? May 25 2007 01:29PM
saudi sans (saudisans gmail com) (3 replies)
Re: [logs] SIM solution - Objectives ? May 28 2007 02:33AM
Mordechai T. Abzug (morty frakir org)
RE: [logs] SIM solution - Objectives ? May 25 2007 06:47PM
Tina Bird (tbird precision-guesswork com) (1 replies)
RE: [logs] SIM solution - Objectives ? May 28 2007 01:00AM
Marcus J. Ranum (mjr ranum com) (1 replies)
RE: [logs] SIM solution - Objectives ? May 29 2007 08:02PM
Paul Melson (pmelson gmail com)
Re: [logs] SIM solution - Objectives ? May 25 2007 05:50PM
Paul Melson (pmelson gmail com) (1 replies)
Re: [logs] SIM solution - Objectives ? (Firewall logging) May 25 2007 06:35PM
Ron Gula (rgula tenablesecurity com) (2 replies)
Re: [logs] SIM solution - Objectives ? (Firewall logging) May 27 2007 03:23PM
Paul Melson (pmelson gmail com) (2 replies)
Re: [logs] SIM solution - Objectives ? (Firewall logging) May 29 2007 03:43PM
Dave Ellingsberg (Dave Ellingsberg csu mnscu edu) (1 replies)
RE: [logs] SIM solution - Objectives ? (Firewall logging) May 30 2007 01:31PM
Paul Melson (pmelson gmail com)
Re: [logs] SIM solution - Objectives ? (Firewall logging) May 27 2007 09:02PM
Marcus J. Ranum (mjr ranum com) (3 replies)
RE: [logs] SIM solution - Objectives ? (Firewall logging) May 29 2007 07:20PM
Eric Fitzgerald (Eric Fitzgerald microsoft com)
Re: [logs] SIM solution - Objectives ? (Firewall logging) May 29 2007 05:17PM
Chris Brenton (cbrenton chrisbrenton org) (1 replies)
Re: [logs] SIM solution - Objectives ? (Firewall logging) May 29 2007 08:53PM
Marcus J. Ranum (mjr ranum com)
[logs] SIM solution - Objectives ? (Firewall logging) May 28 2007 05:59PM
Fenwick, Wynn (wynn fenwick cgi com) (2 replies)
RE: [logs] SIM solution - Objectives ? (Firewall logging) May 29 2007 07:07PM
Paul Melson (pmelson gmail com) (1 replies)
RE: [logs] SIM solution - Objectives ? (Firewall logging) May 30 2007 03:40PM
Fenwick, Wynn (wynn fenwick cgi com) (1 replies)
RE: [logs] SIM solution - Objectives ? (Firewall logging) May 30 2007 09:25PM
Paul Melson (pmelson gmail com) (1 replies)
RE: [logs] SIM solution - Objectives ? (Firewall logging) May 31 2007 07:42PM
Fenwick, Wynn (wynn fenwick cgi com)
[logs] Log Analysis -- Best Practice May 29 2007 06:13AM
harshad mengle wipro com (1 replies)
Re: [logs] Log Analysis -- Best Practice May 30 2007 12:24AM
Ron Gula (rgula tenablesecurity com)
Re: [logs] SIM solution - Objectives ? (Firewall logging) May 25 2007 07:22PM
Jimmy Alderson (jimmy alderson gmail com)


 

Privacy Statement
Copyright 2010, SecurityFocus