tug
Volume 8, Number 31 -- August 28, 2008

Real Time Forensics from Log Data? ArcSight Says It's Got It

Published: August 28, 2008

by Alex Woodie

With the onslaught of identity theft and the increase in instances of corporate data loss these days, forensics is becoming a word more IT administrators are becoming familiar with. In the world of log management solutions, however, most vendors make users choose between speedy log collection and the capability to forensically mine for important system events. With the addition of "forensics on the fly" to its Security Information Event Management (SEIM) system, ArcSight claims users can now do both without compromise.

ArcSight sells several inter-connected products that make up its SIEM platform. It sells an Enterprise Security Management (ESM) product that is geared more toward security than the regulatory compliance end of the collective log. It also sells ArcSight Connectors, which collect logs from more than 275 applications and platforms, and the ArcSight Logger, an integrated appliance for managing logs. Regulatory compliance reporting packages and an identity monitoring product round out the vendor's offerings.

ArcSight says the addition of "forensics on the fly" to the Logger will enable IT and forensics teams to drill down into source events at a moment's notice. As a starting point to the forensics process, the vendor developed a new dashboard interface to the Logger that combines several pertinent reports into a single role-based view. From these dashboards, users can view detailed information, or utilize a new search capability designed to help with root-cause analysis.

When users find violations or other worthwhile events through the search function, they can automatically create alerts that will notify them in real time if the same or similar events occur on the system. ArcSight has also enabled users to drill down into the underlying events directly from the alert.

ArcSight, in effect, has closed the loop between the real-time alerting component of its compliance offering, which was primarily used to detect and notify administrators of regulatory policy violations, and the forensic component of its system, which used to be primarily an "after the fact" activity.

Reed Henry, senior vice president of marketing for ArcSight, provided this perspective: "Our ArcSight ESM [Event Security Management] customers have always enjoyed the ability to drill down from correlated notifications into the events behind those notifications," Henry says in a prepared statement. "With this release of ArcSight Logger, we have added this ability to mine events, or as we call it, forensics on the fly, to our log management products, delivering much needed productivity to log analysis and forensic investigation. Now organizations of any size can quickly and cost effectively conduct informative investigations to determine the root cause of log alert events in real time."

The Cupertino, California, company also recently rolled out a new PCI Logger appliance, which is designed to help customers store log data pertinent to the Payment Card Industry's data security standards (DSS). PCI Logger includes 45 alerts that have been pre-mapped to DSS requirements, as well as the forensics on the fly capability.

ArcSight, which went public less than a year ago on the NASDAQ National Market, also announced its first shareholder meeting. Shareholders of the company, which has enjoyed a 50 percent increase in its stock value since May following flat growth over the first few months of the year, will meet September 25.


RELATED STORY

ArcSight Expands Log Management Offerings



                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
MKS

Meet Your IT Audit and Compliance Demands with MKS

One Seamless Solution for System i and Distributed Application Lifecycle Management

Are you struggling to meet IT audit and compliance demands?
Do you need traceability over software change?

When Pennsylvania Housing Finance Agency (PHFA) needed to achieve compliance, they turned to MKS for traceability over their software change. MKS Integrity enforces their development process and brings end to end traceability to their System i and distributed development operations.

Read the PHFA story.

MKS can help you establish and enforce any software process or workflow, and manage software change from project start to finish. With MKS you can ensure that the application you develop is deployed securely and that only authorized changes go into production.

For auditing and compliance needs, it doesn't get any better than MKS.

For more info, visit http://www.mks.com/itjungle/weareone or call 1 800 613 7535.

Make the Move to MKS now and SAVE!

For a limited time MKS will help you make the move from your existing software change and configuration management solution, with special pricing when you purchase Implementer with MKS Integrity - giving you integrated workflow, complete audit trails and coverage of the application lifecycle as well as a platform to manage both System i and cross-platform development.

Visit the Products section of www.mks.com for more information on Implementer and MKS Integrity.

Click here to request more information on our time limited "change up" offer.

The time is now to make the switch.

Call MKS today at 1-800-613-7535 to discuss your options, and while you're at it,
request a FREE change management process assessment by our team of experts
with over 40 years of experience in the midrange market.

Contact MKS Sales at 1-800-613-7535 or sales@mks.com


Editor: Timothy Prickett Morgan
Contributing Editors: Dan Burger, Joe Hertvik,
Shannon O'Donnell, Timothy Prickett Morgan
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

Vision Solutions:  Click to take a disaster recovery survey, get a $20 gas card!
COMMON:  Join us at the annual 2009 conference, April 26 - April 30, in Reno, Nevada
NowWhatJobs.net:  NowWhatJobs.net is the resource for job transitions after age 40


 

IT Jungle Store Top Book Picks

Getting Started with PHP for i5/OS: List Price, $59.95
The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
The System i Pocket RPG & RPG IV Guide: List Price, $69.95
The iSeries Pocket Database Guide: List Price, $59.00
The iSeries Pocket Developers' Guide: List Price, $59.00
The iSeries Pocket SQL Guide: List Price, $59.00
The iSeries Pocket Query Guide: List Price, $49.00
The iSeries Pocket WebFacing Primer: List Price, $39.00
Migrating to WebSphere Express for iSeries: List Price, $49.00
iSeries Express Web Implementer's Guide: List Price, $59.00
Getting Started with WebSphere Development Studio for iSeries: List Price, $79.95
Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
Getting Started with WebSphere Express for iSeries: List Price, $49.00
WebFacing Application Design and Development Guide: List Price, $55.00
Can the AS/400 Survive IBM?: List Price, $49.00
The All-Everything Machine: List Price, $29.95
Chip Wars: List Price, $29.95


 
The Four Hundred
PowerTech Acquired by Help/Systems, Private Equity Firm

JDA Ponies Up $346 Million to Buy i2 Technologies

SMBs Are Sensibly More Concerned with Biz than Tech

As I See It: Lessons from Robben Island

Big Blue Launches XIV Clustered Storage Arrays

The Linux Beacon
Why Blade Servers Still Don't Cut It, and How They Might

Intel Keeps Both Arms Swinging with Xeons, Jabs with Itanium

Microsoft Ponies Up Another $100 Million for Novell Linux

Mad Dog 21/21: Newtonian Economics

Two More Xeon-Based Galaxy Servers from Sun

Four Hundred Stuff
A Bumblebee for BI--Now That's Just 'Smart'

Curbstone Gains PCI Compliance for i OS Payment System

Life is Easy for iPhone Apps on the Morph Labs Cloud

WebClient for CA Plex 1.4 Now Available

Avnet to Resell VDoc Content Management Suite in U.S.

Big Iron
For Some Customers, the Mainframe Is Green

Top Mainframe Stories From Around the Web

Chats, Webinars, Seminars, Shows, and Other Happenings

Four Hundred Guru
Automatic or Static Storage?

Jetty: An Efficient, Easy to Manage Alternative to WebSphere

Admin Alert: Giving Auditors What They Want

System i PTF Guide
August 23, 2008: Volume 10, Number 34

August 16, 2008: Volume 10, Number 33

August 9, 2008: Volume 10, Number 32

August 2, 2008: Volume 10, Number 31

July 26, 2008: Volume 10, Number 30

July 19, 2008: Volume 10, Number 29

The Windows Observer
Citrix Addresses Performance with XenApp 5

Server Buyers Shop Like It's 1999 in the Second Quarter

Intel Keeps Both Arms Swinging with Xeons, Jabs with Itanium

Mad Dog 21/21: Newtonian Economics

Microsoft Does Something About Those SQL Injection Attacks

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

THIS ISSUE SPONSORED BY:

Vibrant Technologies
Centrify
Canvas Systems
Guild Companies
MKS


Printer Friendly Version


TABLE OF CONTENTS
Why Blade Servers Still Don't Cut It, and How They Might

Intel Keeps Both Arms Swinging with Xeons, Jabs with Itanium

Server Buyers Shop Like It's 1999 in the Second Quarter

As I See It: God Bless Technology

Gartner Is Projecting a Decline in IT Hiring This Year

But Wait, There's More:

Reader Feedback on What the Heck Is the Midrange, Anyway? . . . SMBs Are Sensibly More Concerned with Biz than Tech . . . Middleware Makers Are Sued Over Server Patents . . . Avnet Buys Ontrack for Asian Expansion . . . Real Time Forensics from Log Data? ArcSight Says It's Got It . . .

The Unix Guardian

BACK ISSUES





 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2008 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement