• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • Pat Townsend Normalizes i5/OS Log Data for Security Analyses

    October 9, 2007 Alex Woodie

    There are many advantages to using a System i server to run business applications, including high degrees of security, scalability, and reliability. But there are also disadvantages to the proprietary platform, such as the fact that its security log data is incompatible with industry standard formats used by Windows, Unix, and Linux machines, which poses a challenge to security event correlation. Last week, i5/OS software vendor Patrick Townsend & Associates launched a new product, called the Alliance LogAgent, that transforms i5/OS log data into the industry standard “syslog” format.

    It used to be that nobody paid much attention to the various computer logs and audit journals that document the day-to-day processes of a business machine. They existed mostly in the background, storing tons of raw data only the most die-hard geeks could understand, let alone derive benefit from.

    But now, we’re in the midst of a security log renaissance. Regulations such as PCI, SOX, and HIPAA are leading companies to delve into their server logs like never before, determined to find evidence of a hacking ring, confirmation of organized crime, or traces of unauthorized internal access–or just to get the auditors off their backs. Equipped with advanced security information and event management (SIEM) systems, forensic investigators and chief security officers rely on the raw data provided by logs to bring down the bad guys. There’s almost something sexy about security logs.

    And while a System i server is less likely to be hacked than your average Linux or Windows box, the platform hasn’t been participating in the security log revolution to the same extent as its “open systems” brethren. The reason for this is that, while the rest of the computing world has largely agreed to use the syslog protocol, IBM has steadfastly maintained its own proprietary log data format for the i5/OS server.

    With Alliance LogAgent, Pat Townsend is addressing the System i’s separation from the SIEM marketplace and the capability of SIEM products to correlate the security data from all IT assets–including servers, databases, and network devices–thereby boosting overall security. The product does this by translating data collected from the i5/OS logs, such as the QAUDJRN and QSYSOPR journals, as well as application messages and SNMP traps, into the RFC 3164 protocol, which is the standard format used by major SIEM products, according to Pat Townsend.

    The software also digs up and translates critical System i security data that may be missed if the QAUDJRN journal is the only place you look. Because several popular open-source applications for the System i–such as the Apache Web server, the MySQL database, and applications written in PHP–store their log data on the IFS, it can be easily overlooked. Integration with other Pat Townsend network products, including Alliance FTP Manager, Alliance XML/400, and Alliance AS2 Integrator, provides more grist for the SIEM security data mill.

    Once translated to RFC 3164 format, i5/OS security event information can be shared with many cross-platform SIEM systems that use the syslog standard, including the open source Syslogd application that’s available for Unix and Linux, and several commercial offerings, including ArcSight‘s ESM, Symantec SIM, LogLogic‘s LX, Novell‘s Sentinel, Q1Labs‘ QRadar, TriGeo‘s SIM, and CrossTec‘s Activeworx, Pat Townsend says. These products provide benefits in the area of real-time alerting, as well as after-the-fact reporting.

    The product also comes with tools that allow users to define their own System i security events, and interfaces for integrating Alliance LogAgent routines into ILE applications. With this latter capability, Pat Townsend expects the product to be a good seller among ISVs.

    Alliance LogAgent is largely based on the open source Syslogd application sold and supported by BalaBit. Pat Townsend ported it to run on the System i, and provided the i5/OS know-how to make the product really fit into this peculiar platform.

    In addition to gaining a more complete picture of one’s security posture, Alliance LogAgent can also help free up gigabytes of valuable disk space on the System i, providing a cost savings. Users can cut down on their bandwidth requirements by filtering the events sent to the SIEM, while offloading archive log data onto cheaper Windows and Linux servers can bring additional savings.

    Pat Townsend, president of the Olympia, Washington, company, says the effectiveness of log analysis and management software depends on the capability to consolidate all security and event data into one place. “Only then can patterns be analyzed for potential security breaches,” he says. “By providing a System i log agent and integrating all of our encryption and data security solutions into the logging architecture, our customers get unmatched support for security monitoring.”

    Alliance LogAgent is available now. The product requires OS/400 V5R1 or higher. For more information, visit www.patownsend.com.

    RELATED STORIES

    Patrick Townsend Brings 256-Bit AES Encryption to DB2/400 Data

    Pat Townsend Teams with iSoft for Native OS/400 AS2 EDI-INT Software

    PowerTech to Resell 256-Bit Encryption from Pat Townsend



                         Post this story to del.icio.us
                   Post this story to Digg
        Post this story to Slashdot

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Tags:

    Sponsored by
    WorksRight Software

    Do you need area code information?
    Do you need ZIP Code information?
    Do you need ZIP+4 information?
    Do you need city name information?
    Do you need county information?
    Do you need a nearest dealer locator system?

    We can HELP! We have affordable AS/400 software and data to do all of the above. Whether you need a simple city name retrieval system or a sophisticated CASS postal coding system, we have it for you!

    The ZIP/CITY system is based on 5-digit ZIP Codes. You can retrieve city names, state names, county names, area codes, time zones, latitude, longitude, and more just by knowing the ZIP Code. We supply information on all the latest area code changes. A nearest dealer locator function is also included. ZIP/CITY includes software, data, monthly updates, and unlimited support. The cost is $495 per year.

    PER/ZIP4 is a sophisticated CASS certified postal coding system for assigning ZIP Codes, ZIP+4, carrier route, and delivery point codes. PER/ZIP4 also provides county names and FIPS codes. PER/ZIP4 can be used interactively, in batch, and with callable programs. PER/ZIP4 includes software, data, monthly updates, and unlimited support. The cost is $3,900 for the first year, and $1,950 for renewal.

    Just call us and we’ll arrange for 30 days FREE use of either ZIP/CITY or PER/ZIP4.

    WorksRight Software, Inc.
    Phone: 601-856-8337
    Fax: 601-856-9432
    Email: software@worksright.com
    Website: www.worksright.com

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Sponsored Links

    SafeData:  The iSeries HA Solution that’s Guaranteed
    COMMON:  Join us at the annual 2008 conference, March 30 - April 3, in Nashville, Tennessee
    NowWhatJobs.net:  NowWhatJobs.net is the resource for job transitions after age 40

    IT Jungle Store Top Book Picks

    The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
    The System i Pocket RPG & RPG IV Guide: List Price, $69.95
    The iSeries Pocket Database Guide: List Price, $59.00
    The iSeries Pocket Developers' Guide: List Price, $59.00
    The iSeries Pocket SQL Guide: List Price, $59.00
    The iSeries Pocket Query Guide: List Price, $49.00
    The iSeries Pocket WebFacing Primer: List Price, $39.00
    Migrating to WebSphere Express for iSeries: List Price, $49.00
    iSeries Express Web Implementer's Guide: List Price, $59.00
    Getting Started with WebSphere Development Studio for iSeries: List Price, $79.95
    Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
    Getting Started with WebSphere Express for iSeries: List Price, $49.00
    WebFacing Application Design and Development Guide: List Price, $55.00
    Can the AS/400 Survive IBM?: List Price, $49.00
    The All-Everything Machine: List Price, $29.95
    Chip Wars: List Price, $29.95

    What Are Else Are Employees Up To? Shopping Online During Con Calls Controlling System i Shutdown Activities Using an Intelligent Power-Handling Program, Part I

    Leave a Reply Cancel reply

Volume 7, Number 38 -- October 9, 2007
THIS ISSUE SPONSORED BY:

BOSaNOVA
Aldon
nuBridges
Computer Measurement Group
RJS Software Systems

Table of Contents

  • ACOM Updates EZ Content Manager
  • looksoftware’s Modernization Suite Resembling a Full IDE
  • Pat Townsend Normalizes i5/OS Log Data for Security Analyses
  • Linoma Boosts Surveyor/400’s SQL Functionality
  • PowerTech Updates Compliance Manager
  • IBM Comments on iSeries Access and Windows Vista
  • Update on Virtualization Manager’s i5/OS LPAR Capabilities
  • Raz-Lee Supports SSL in i5/OS Firewall
  • Inventive Designers Launches DTM for iSeries Version 3
  • Optio Software Saves Manufacturer from the Paper Chase

Content archive

  • The Four Hundred
  • Four Hundred Stuff
  • Four Hundred Guru

Recent Posts

  • Public Preview For Watson Code Assistant for i Available Soon
  • COMMON Youth Movement Continues at POWERUp 2025
  • IBM Preserves Memory Investments Across Power10 And Power11
  • Eradani Uses AI For New EDI And API Service
  • Picking Apart IBM’s $150 Billion In US Manufacturing And R&D
  • FAX/400 And CICS For i Are Dead. What Will IBM Kill Next?
  • Fresche Overhauls X-Analysis With Web UI, AI Smarts
  • Is It Time To Add The Rust Programming Language To IBM i?
  • Is IBM Going To Raise Prices On Power10 Expert Care?
  • IBM i PTF Guide, Volume 27, Number 20

Subscribe

To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

Pages

  • About Us
  • Contact
  • Contributors
  • Four Hundred Monitor
  • IBM i PTF Guide
  • Media Kit
  • Subscribe

Search

Copyright © 2025 IT Jungle