|
LogAnalysis
[logs] Eventlog to syslog Feb 29 2008 12:59PM Marcelo de Souza (marcelo marcelosouza com) (3 replies) Re: [logs] Eventlog to syslog Mar 06 2008 10:49PM Anton Chuvakin (anton chuvakin org) (1 replies) [logs] SYSLOG patent? Mar 12 2008 08:16AM A Ananth (ananth802 yahoo com) (1 replies) Re: [logs] SYSLOG patent? Mar 14 2008 11:18AM Stefano Zanero (zanero elet polimi it) (1 replies) Re: [logs] SYSLOG patent? Mar 14 2008 04:22PM Balazs Scheidler (bazsi balabit hu) (4 replies) RE: [logs] SYSLOG patent? Mar 14 2008 06:22PM Rainer Gerhards (rgerhards hq adiscon com) (2 replies) Re: [logs] Eventlog to syslog Feb 29 2008 07:27PM tbird precision-guesswork com (2 replies) Re: [logs] Eventlog to syslog Feb 29 2008 09:10PM David Corlette (DCorlette novell com) (1 replies) [logs] wny not syslog on microsoft platforms Feb 29 2008 11:13PM Rodney Thayer (rodney canola-jones com) Re: [logs] Eventlog to syslog Feb 29 2008 08:52PM Rodney Thayer (rodney canola-jones com) (2 replies) Re: [logs] Eventlog to syslog Feb 29 2008 10:17PM tbird precision-guesswork com (4 replies) Re: [logs] Eventlog to syslog Feb 29 2008 11:46PM Andrew Hay (andrewsmhay gmail com) (2 replies) Re: [logs] Eventlog to syslog Mar 01 2008 02:31AM A Ananth (ananth802 yahoo com) (1 replies) |
|
Privacy Statement |
Hi Patrick,
MOM as a SIEM tool? Ouch.
There are a bunch of real SIEM tools out there; MOM's not one of them. Disclaimer here, I work on Sentinel, where our approach is that we accept whatever you throw at us: syslog, WMI, JDBC, OPSEC LEA, really anything. But we also apply some intelligence to the inbound data, integrate identity data and asset data, correlate IDS and vulnerability information, so on and so forth. Any other real SIEM tool will do the same, but not MOM.
Incidentally, it would be perfectly possible to use our tool to accept WMI (or JDBC, or any other format data) and spit it back out as syslog. This wouldn't be a very good way to do it, as of course what you want to provide on the backend is a nice query-able datastore which is what we offer, but we've done it for some customers that already have a SIEM tool in place and are just using Sentinel to monitor Novell apps.
> I realize I am diverging a bit from the original discussion of MS support of
> the
> syslog transport, but given the existence of MOM and it's apparent support
> of
> syslog, it seems inevitable that the discussion (at least with my employer)
> will
> eventually lead down the path of MOM's abilities as a heterogeneous event
> analysis (i.e. SEM) tool.
>
> thx,
> -pat.
_______________________________________________
LogAnalysis mailing list
LogAnalysis (at) loganalysis (dot) org [email concealed]
http://www.loganalysis.org/mailman/listinfo/loganalysis
[ reply ]