|
LogAnalysis
[logs] Eventlog to syslog Feb 29 2008 12:59PM Marcelo de Souza (marcelo marcelosouza com) (3 replies) Re: [logs] Eventlog to syslog Mar 06 2008 10:49PM Anton Chuvakin (anton chuvakin org) (1 replies) [logs] SYSLOG patent? Mar 12 2008 08:16AM A Ananth (ananth802 yahoo com) (1 replies) Re: [logs] SYSLOG patent? Mar 14 2008 11:18AM Stefano Zanero (zanero elet polimi it) (1 replies) Re: [logs] SYSLOG patent? Mar 14 2008 04:22PM Balazs Scheidler (bazsi balabit hu) (4 replies) RE: [logs] SYSLOG patent? Mar 14 2008 06:22PM Rainer Gerhards (rgerhards hq adiscon com) (2 replies) Re: [logs] Eventlog to syslog Feb 29 2008 07:27PM tbird precision-guesswork com (2 replies) Re: [logs] Eventlog to syslog Feb 29 2008 09:10PM David Corlette (DCorlette novell com) (1 replies) [logs] wny not syslog on microsoft platforms Feb 29 2008 11:13PM Rodney Thayer (rodney canola-jones com) Re: [logs] Eventlog to syslog Feb 29 2008 08:52PM Rodney Thayer (rodney canola-jones com) (2 replies) Re: [logs] Eventlog to syslog Feb 29 2008 10:17PM tbird precision-guesswork com (4 replies) Re: [logs] Eventlog to syslog Mar 03 2008 07:08PM Patrick Hull (nethead69 gmail com) (2 replies) |
|
Privacy Statement |
--- Andrew Hay <andrewsmhay (at) gmail (dot) com [email concealed]> wrote:
> I suspect that, with the (future) adoption of
> Windows 2008 and the new
> cross-log query feature in the event log (that
> allows you to correlate logs
> from multiple systems), Microsoft may finally have
> put the nail in the
> coffin that is this issue (at least in their eyes).
> I'll be honest, I
> haven't dug into the new event log due to other
> things on my plate, but I
> have a feeling that this new event log rewrite is
> going to be positioned as
> a SIEM replacement for Windows based events.
If Microsoft feels that the 'cross-log query' feature
nails the SIEM problem -- we disagree. It opens up
some possibilities for very small shops but by itself
has limited value in even a medium size install.
Limitations
1) All machines must run Vista
2) Collector is a workstation
3) Event automation is local to each system
4) No central policy mgt console
5) Updating each endpoint system is manual effort
6) Its an MS-standard
We explored the Vista event log in a webinar last year
with Nelson Ruest. Its online (registration required)
at
http://www.prismmicrosys.com/webinarDetails.php?id=10&a=view
Disclaimer: I'm with Prism, a SIEM vendor
--
A Ananth
ananth802 (at) yahoo (dot) com [email concealed]
--
A N Ananth
ananth802 (at) yahoo (dot) com [email concealed]
_______________________________________________
LogAnalysis mailing list
LogAnalysis (at) loganalysis (dot) org [email concealed]
http://www.loganalysis.org/mailman/listinfo/loganalysis
[ reply ]