fhs
Volume 10, Number 33 -- September 21, 2010

ArcSight Updates SIEM Platform

Published: September 21, 2010

by Alex Woodie

ArcSight, which is being acquired by Hewlett-Packard for $1.5 billion, last week unveiled enhancements to its security information and event management (SIEM) platform, including its Enterprise Security Manager (ESM) offering and its log management solution, called Logger.

Several inter-connected products make up ArcSight's SIEM platform, which the company claims is the most widely used SIEM solution in the world. When you consider that the company claims more than 100 banks, the government systems of over 30 nations, more than 55 U.S. Federal agencies, and more than 50 telecommunication service providers as customers, then you're forced to conclude that ArcSight really know its stuff.

At the core of the suite is ArcSight ESM, a Windows-, Unix-, or Linux-installed product that does the grunt work of chewing through millions of security log files collected from customer's networks, databases, IBM i and mainframe apps, and physical security devices; connecting suspicious events through advanced correlation algorithms; and then alerting administrators to potential security events. All this is done fairly automatically and in real-time, which means it takes a lot of iron and is not cheap to install or run.

ArcSight ESM 5.0 features a new user risk monitoring framework that's designed to analyze the behavior of users, and ferret out possible threats emanating from inside the organization. Security studies repeatedly show that about two in three security breaches are perpetrated from internal users, even though hackers coming in over the Internet get most of the media glory.

Tom Reilly, president and CEO of ArcSight, says organizations are realizing they need to become "multidimensional" in how they build security protections. "Organizations can no longer simply look for external attacks as the only threat," Reilly says in a press release.

Other enhancements in ESM 5.0--including a new Web services API, a new developer framework, and the addition of industry-specific field sets for the creation of custom SIEM applications--are geared toward making it easier for other vendors to tap into the ArcSight SIEM, and building out the ArcSight partner base. HP, as the world's largest IT vendor, will undoubtedly look to leverage these new third-party hooks far and wide.

With Logger 5.0, ArcSight has worked to simplify searching and report generation. The company added the capability to create reports against structured and unstructured data, and also introduced a new search language for people who prefer "iterative" searches, the company says. It also added new capabilities for tracking application build errors, failed log in attempts, and CPU utilization.

The vendor also expanded the ways in which people can use Logger. The product, which was previously sold only as an appliance, is now available as downloadable software, as a Web-based service accessed from Amazon, or as an appliance. Downloads start at $49, while the appliance version starts at $20,000.

ArcSight also unveiled IdentityView 2.0, a new release of its user activity monitoring solution. Version 2.0 bring enhancements that will enable customers to "better understand who is on the network, what they are doing, and how that affects business risk," the vendor says.

ArcSight made the product announcements from ArcSight Protect '10, its annual user conference, which is being held this week in Washington, D.C. The company, which went public in 2008 and brought in about $181 million in revenue last year, announced last week that it's being acquired by HP for $43.50 per share. The acquisition is expected to be completed by the end of 2010.


RELATED STORIES

ArcSight Delivers SIEM to Mid Market Customers

Real Time Forensics from Log Data? ArcSight Says It's Got It

ArcSight Expands Log Management Offerings



                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
VISION SOLUTIONS

FREE SYSTEM i UTILITY!

Quickly see the health of your System i.

A free, no-license, self-installing System i utility,iSCORE™
from Vision Solutions quickly produces a simple,
clear report that outlines the overall operating
health of either your entire System i or a selected LPAR.

Click to download now.


Editor: Alex Woodie
Contributing Editors: Dan Burger, Joe Hertvik,
Shannon O'Donnell, Timothy Prickett Morgan
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

PowerTech:  FREE Webinar! Reduce the Cost and Effort of IBM i Auditing. Sept. 29, 10 a.m. CT
looksoftware:  RPG OA & Beyond Webinar. Sept 28 & 29. Enter to win an Amazon Kindle™
COMMON:  Join us at the Fall 2010 Conference & Expo, Oct. 4 - 6, in San Antonio, Texas


 

IT Jungle Store Top Book Picks

Easy Steps to Internet Programming for AS/400, iSeries, and System i: List Price, $49.95
The iSeries Express Web Implementer's Guide: List Price, $49.95
The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
The System i Pocket RPG & RPG IV Guide: List Price, $69.95
The iSeries Pocket Database Guide: List Price, $59.00
The iSeries Pocket SQL Guide: List Price, $59.00
The iSeries Pocket Query Guide: List Price, $49.00
The iSeries Pocket WebFacing Primer: List Price, $39.00
Migrating to WebSphere Express for iSeries: List Price, $49.00
Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
Getting Started with WebSphere Express for iSeries: List Price, $49.00
Can the AS/400 Survive IBM?: List Price, $49.00
Chip Wars: List Price, $29.95


 
The Four Hundred
The More Things Change

Big Sam Is Worried About Oracle--And For Good Reason

Focus Melds Crowdsourced IT Analysis with Social Media

Mad Dog 21/21: Seismically Active Storage

IBM Gives Schools Discounts on Power Systems Iron

Four Hundred Guru
Get Thee to the Web, Part 2

Basing Pointer Variables in RPG: The Basics

Admin Alert: Getting Started with i/OS Security Auditing, Part 1

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

System i PTF Guide
September 4, 2010: Volume 12, Number 36

August 28, 2010: Volume 12, Number 35

August 21, 2010: Volume 12, Number 34

August 14, 2010: Volume 12, Number 33

August 7, 2010: Volume 12, Number 32

July 31, 2010: Volume 12, Number 31

TPM at The Register
Larry Ellison's first Sparc chip and server

Blade Network adds top-of-racker

IBM ponies up $1.7bn for data warehouse maker

HP tunes blades for Oracle apps

Dell nestles baby Opterons into PowerEdge racks

HP reported close to naming Hurd successor

Ellison: 'We can double Oracle's hardware biz'

Revolution links R stats package to apps

Novell breakup and sale imminent, says report

Cisco to pay divvy in 2011

Intel and VC friends kick cash to IT startups

OpenSolaris spork ready for download

THIS ISSUE SPONSORED BY:

LANSA
Bytware
RevSoft
Vision Solutions
DRV Technologies


Printer Friendly Version


TABLE OF CONTENTS
Pat Townsend Bolsters MFT Lineup with New Encryption Options

Linoma Fleshes Out MFT Line with Reverse Proxy Solution

Consonus Offers Online Backups for IBM i Data

Raz-Lee Bolsters IBM i Security Analysis Tool

IBM Updates Guardium Database Security Software

News Briefs and Product Shorts:

SaaS Vendor Gets Solid Network Links to IBM i Apps . . . MuleSoft Updates Open Source ESB . . . IBM Wants to Buy Netezza for $1.7 Billion . . . ArcSight Updates SIEM Platform . . . Is RFID Heyday Just Around the Corner? . . .

Four Hundred Stuff

BACK ISSUES




 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2010 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement