• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • ArcSight Expands Log Management Offerings

    November 13, 2007 Alex Woodie

    ArcSight, an established vendor of security information and event management (SIEM) software that’s planning an IPO, this week announced a new appliance-based log management product it says will make it easier for companies to comply with mandates like Sarbanes-Oxley and PCI. The new offering, called the Log Management Suite, will do this by streamlining the collection and storage of log data from disparate sources, and then simplifying the generation of compliance reports and dashboards that auditors create from log data.

    Since ArcSight was founded by security software veteran Hugh Njemanze in 2000, the Cupertino, California, company has been selling a lot of licenses for ArcSight ESM, its flagship SIEM product designed to alert administrators to break-ins and other violations of their security policy–hopefully as they occur, or soon thereafter. More than 350 organizations, including some of the biggest names in defense, energy, financial services, and healthcare, and about 20 major U.S. government agencies, have bought ArcSight ESM, and the product has received rave reviews from Gartner, among others.

    While ArcSight has developed a solid reputation on the SIEM front and has good prospects in the field, which IDC says will grow from $993.6 million in 2007 to $2.2 billion in 2011, the company has worked to diversify its offerings by developing solutions in slightly different but related fields, including network and configuration management and the broad compliance management market. This shift was easier thanks to the rich assortment of connectors the company had developed for ArcSight ESM, which allows the SIEM product to process log data sent to it from various operating systems, databases, applications, and network devices. Currently, that connector collection numbers about 180, and includes connectors for IBM System i and System z servers, which the company views as a strategic advantage.

    But having deep and broad access to log files stored on servers and network devices is a mixed blessing. While it’s mandated by regulations like SOX, PCI, HIPAA, FISMA, GLBA, and JSOX (Japan’s version of SOX), the flood of log data is swamping companies, says Ansh Patnaik, senior product marketing manager for ArcSight. “The fundamental challenge that organizations face is how do I capture all this data, especially from legacy sources, and then how can I automate audits and easily extend access to different consumers, in particular auditors, but also other constituents?”

    About a year ago, ArcSight rolled out its first log management appliance, called the Logger. This product was designed to be installed at a company’s headquarters, where it stores terabytes worth of log data sent to it by agent-based software products installed on the target devices. It could process 75,000 events per second.

    However, there were problems with the agent-based approach used with the first-generation product, according to Patnaik. Running more software on servers makes them run slower, and can interfere with the actual work. After all, you don’t buy a server to generate log files–you buy it to record your sales and process other transactions.

    ArcSight addressed this problem with the new Log Management Suite, part of which includes three appliances that handle the log collection workload and compress and encrypt the data before sending it off to the big log archive located at headquarters. “The idea is to be within that trusted network so you’re collecting remotely, and you can ensure secure and reliable transfer of all logs from all sources back to the central site, but to do it off-board, so you don’t impact the actual servers that are generating the logs,” Patnaik says.

    The appliances are rack-mountable servers powered by dual-core AMD Opteron processors and a Linux variant. They include the low-end L3000M appliance, which supports up to 2,000 events per second (EPS) and costs $20,000; the midrange L5000S, which scales up to 5,000 EPS and costs around $50,000; and the big dog, the L5000X, which can process up to 100,000 EPS and costs (you guessed it) $100,000. While the line has more high-end oomph than it did previously, ArcSight expects more success with the entry-level and midrange boxes.

    The other side of the Log Management Suite is new software designed to make it easier for auditors to do their jobs. This includes a new reporting portal that gives auditors the capability to automate much of the work involved in creating their reports, so the IT department doesn’t have to do it for them.

    The new software also provides auditors with personalized dashboard views, “so they don’t have to sift through hundred of reports that are device-specific and instead they get meaningful relevant views into the state of audits or the state of compliance,” Patnaik says. From there, “they can quickly drill down from the top-level view into more granular queries and investigate further and look for root-cause analysis or why the violations were occurring, so there’s a very intuitive view into compliance.” ArcSight also sells a variety of reporting packs for specific regulations.

    ArcSight’s support for IBM System i and System z servers gives it an advantage as users of these systems look for ways to automate their compliance initiatives, Patnaik says. “The general trend in log management has been, for compliance you need to collect logs, and typically they’re protocol-level collection, so Syslog covers quite a few devices at the security and network layers,” he says. “We have support for mainframes and midrange servers as well, and that tends to be important in a compliance context because very often application data resides in these types of mainframes and midrange boxes.”

    While the Syslog provides some commonality, the industry is far from settling on a single log event standard, which keeps the money flowing to companies like ArcSight that can smooth over the differences. “Each log has its syntax; each device has its own syntax. We’ve abstracted that by providing one common taxonomy, and that’s what all the reports and dashboards are built on,” Patnaik says.



                         Post this story to del.icio.us
                   Post this story to Digg
        Post this story to Slashdot

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Tags:

    Sponsored by
    DRV Tech

    Get More Out of Your IBM i

    With soaring costs, operational data is more critical than ever. IBM shops need faster, easier ways to distribute IBM applications-based data to users more efficiently, no matter where they are.

    The Problem:

    For Users, IBM Data Can Be Difficult to Get To

    IBM Applications generate reports as spooled files, originally designed to be printed. Often those reports are packed together with so much data it makes them difficult to read. Add to that hardcopy is a pain to distribute. User-friendly formats like Excel and PDF are better, offering sorting, searching, and easy portability but getting IBM reports into these formats can be tricky without the right tools.

    The Solution:

    IBM i Reports can easily be converted to easy to read and share formats like Excel and PDF and Delivered by Email

    Converting IBM i, iSeries, and AS400 reports into Excel and PDF is now a lot easier with SpoolFlex software by DRV Tech.  If you or your users are still doing this manually, think how much time is wasted dragging and reformatting to make a report readable. How much time would be saved if they were automatically formatted correctly and delivered to one or multiple recipients.

    SpoolFlex converts spooled files to Excel and PDF, automatically emailing them, and saving copies to network shared folders. SpoolFlex converts complex reports to Excel, removing unwanted headers, splitting large reports out for individual recipients, and delivering to users whether they are at the office or working from home.

    Watch our 2-minute video and see DRV’s powerful SpoolFlex software can solve your file conversion challenges.

    Watch Video

    DRV Tech

    www.drvtech.com

    866.378.3366

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Sponsored Links

    ARCAD Software:  Dynamic, world-class ALM on and around the System i
    COMMON:  Join us at the annual 2008 conference, March 30 - April 3, in Nashville, Tennessee
    NowWhatJobs.net:  NowWhatJobs.net is the resource for job transitions after age 40

    IT Jungle Store Top Book Picks

    The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
    The System i Pocket RPG & RPG IV Guide: List Price, $69.95
    The iSeries Pocket Database Guide: List Price, $59.00
    The iSeries Pocket Developers' Guide: List Price, $59.00
    The iSeries Pocket SQL Guide: List Price, $59.00
    The iSeries Pocket Query Guide: List Price, $49.00
    The iSeries Pocket WebFacing Primer: List Price, $39.00
    Migrating to WebSphere Express for iSeries: List Price, $49.00
    iSeries Express Web Implementer's Guide: List Price, $59.00
    Getting Started with WebSphere Development Studio for iSeries: List Price, $79.95
    Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
    Getting Started with WebSphere Express for iSeries: List Price, $49.00
    WebFacing Application Design and Development Guide: List Price, $55.00
    Can the AS/400 Survive IBM?: List Price, $49.00
    The All-Everything Machine: List Price, $29.95
    Chip Wars: List Price, $29.95

    Fujifilm Adds GPS Tracker to Tape Cartridges ON vs. WHERE

    Leave a Reply Cancel reply

Volume 7, Number 43 -- November 13, 2007
THIS ISSUE SPONSORED BY:

Aldon
New Generation Software
Maximum Availability
Computer Keyes
Twin Data

Table of Contents

  • PowerTech Ships i5/OS Syslog Connector for SIEM
  • Change Management Software Gets Boost from Mighty Ant
  • Attachmate Ships Emulator, Touts Tolly Report
  • BCD Delivers Major Update of WebSmart ILE
  • ArcSight Expands Log Management Offerings
  • Nulogx to Sell ACOM’s EZeDocs/400 with Hosted TMS
  • Bytware i5 Security Campaign Gaining World Recognition
  • BOSaNOVA Encryption Device Supports Multiple Tape Drives
  • IBM VIPs Gives Infor Another ‘A+’ Role
  • Oracle Launches ‘Business Accelerator’ for J.D. Edwards EnterpriseOne

Content archive

  • The Four Hundred
  • Four Hundred Stuff
  • Four Hundred Guru

Recent Posts

  • Meet The Next Gen Of IBMers Helping To Build IBM i
  • Looks Like IBM Is Building A Linux-Like PASE For IBM i After All
  • Will Independent IBM i Clouds Survive PowerVS?
  • Now, IBM Is Jacking Up Hardware Maintenance Prices
  • IBM i PTF Guide, Volume 27, Number 24
  • Big Blue Raises IBM i License Transfer Fees, Other Prices
  • Keep The IBM i Youth Movement Going With More Training, Better Tools
  • Remain Begins Migrating DevOps Tools To VS Code
  • IBM Readies LTO-10 Tape Drives And Libraries
  • IBM i PTF Guide, Volume 27, Number 23

Subscribe

To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

Pages

  • About Us
  • Contact
  • Contributors
  • Four Hundred Monitor
  • IBM i PTF Guide
  • Media Kit
  • Subscribe

Search

Copyright © 2025 IT Jungle