• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • ArcSight Updates SIEM Platform

    September 21, 2010 Alex Woodie

    ArcSight, which is being acquired by Hewlett-Packard for $1.5 billion, last week unveiled enhancements to its security information and event management (SIEM) platform, including its Enterprise Security Manager (ESM) offering and its log management solution, called Logger.

    Several inter-connected products make up ArcSight’s SIEM platform, which the company claims is the most widely used SIEM solution in the world. When you consider that the company claims more than 100 banks, the government systems of over 30 nations, more than 55 U.S. Federal agencies, and more than 50 telecommunication service providers as customers, then you’re forced to conclude that ArcSight really know its stuff.

    At the core of the suite is ArcSight ESM, a Windows-, Unix-, or Linux-installed product that does the grunt work of chewing through millions of security log files collected from customer’s networks, databases, IBM i and mainframe apps, and physical security devices; connecting suspicious events through advanced correlation algorithms; and then alerting administrators to potential security events. All this is done fairly automatically and in real-time, which means it takes a lot of iron and is not cheap to install or run.

    ArcSight ESM 5.0 features a new user risk monitoring framework that’s designed to analyze the behavior of users, and ferret out possible threats emanating from inside the organization. Security studies repeatedly show that about two in three security breaches are perpetrated from internal users, even though hackers coming in over the Internet get most of the media glory.

    Tom Reilly, president and CEO of ArcSight, says organizations are realizing they need to become “multidimensional” in how they build security protections. “Organizations can no longer simply look for external attacks as the only threat,” Reilly says in a press release.

    Other enhancements in ESM 5.0–including a new Web services API, a new developer framework, and the addition of industry-specific field sets for the creation of custom SIEM applications–are geared toward making it easier for other vendors to tap into the ArcSight SIEM, and building out the ArcSight partner base. HP, as the world’s largest IT vendor, will undoubtedly look to leverage these new third-party hooks far and wide.

    With Logger 5.0, ArcSight has worked to simplify searching and report generation. The company added the capability to create reports against structured and unstructured data, and also introduced a new search language for people who prefer “iterative” searches, the company says. It also added new capabilities for tracking application build errors, failed log in attempts, and CPU utilization.

    The vendor also expanded the ways in which people can use Logger. The product, which was previously sold only as an appliance, is now available as downloadable software, as a Web-based service accessed from Amazon, or as an appliance. Downloads start at $49, while the appliance version starts at $20,000.

    ArcSight also unveiled IdentityView 2.0, a new release of its user activity monitoring solution. Version 2.0 bring enhancements that will enable customers to “better understand who is on the network, what they are doing, and how that affects business risk,” the vendor says.

    ArcSight made the product announcements from ArcSight Protect ’10, its annual user conference, which is being held this week in Washington, D.C. The company, which went public in 2008 and brought in about $181 million in revenue last year, announced last week that it’s being acquired by HP for $43.50 per share. The acquisition is expected to be completed by the end of 2010.

    RELATED STORIES

    ArcSight Delivers SIEM to Mid Market Customers

    Real Time Forensics from Log Data? ArcSight Says It’s Got It

    ArcSight Expands Log Management Offerings



                         Post this story to del.icio.us
                   Post this story to Digg
        Post this story to Slashdot

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Tags:

    Sponsored by
    New Generation Software

    FREE Webinar:

    Creating Great Data for Enterprise AI

    Enterprise AI relies on many data sources and types, but every AI project needs a data quality, governance, and security plan.

    Wherever and however you want to analyze your data, adopting modern ETL and BI software like NGS-IQ is a great way to support your effort.

    Webinar: June 26, 2025

    RSVP today.

    www.ngsi.com – 800-824-1220

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Sponsored Links

    PowerTech:  FREE Webinar! Reduce the Cost and Effort of IBM i Auditing. Sept. 29, 10 a.m. CT
    looksoftware:  RPG OA & Beyond Webinar. Sept 28 & 29. Enter to win an Amazon Kindle™
    COMMON:  Join us at the Fall 2010 Conference & Expo, Oct. 4 - 6, in San Antonio, Texas

    IT Jungle Store Top Book Picks

    Easy Steps to Internet Programming for AS/400, iSeries, and System i: List Price, $49.95
    The iSeries Express Web Implementer's Guide: List Price, $49.95
    The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
    The System i Pocket RPG & RPG IV Guide: List Price, $69.95
    The iSeries Pocket Database Guide: List Price, $59.00
    The iSeries Pocket SQL Guide: List Price, $59.00
    The iSeries Pocket Query Guide: List Price, $49.00
    The iSeries Pocket WebFacing Primer: List Price, $39.00
    Migrating to WebSphere Express for iSeries: List Price, $49.00
    Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
    Getting Started with WebSphere Express for iSeries: List Price, $49.00
    Can the AS/400 Survive IBM?: List Price, $49.00
    Chip Wars: List Price, $29.95

    Lab Services and Training Available for Power Systems Shops Get Thee to the Web, Part 3

    Leave a Reply Cancel reply

Volume 10, Number 33 -- September 21, 2010
THIS ISSUE SPONSORED BY:

LANSA
Bytware
RevSoft
Vision Solutions
DRV Technologies

Table of Contents

  • Pat Townsend Bolsters MFT Lineup with New Encryption Options
  • Linoma Fleshes Out MFT Line with Reverse Proxy Solution
  • Consonus Offers Online Backups for IBM i Data
  • Raz-Lee Bolsters IBM i Security Analysis Tool
  • IBM Updates Guardium Database Security Software
  • SaaS Vendor Gets Solid Network Links to IBM i Apps
  • MuleSoft Updates Open Source ESB
  • IBM Wants to Buy Netezza for $1.7 Billion
  • ArcSight Updates SIEM Platform
  • Is RFID Heyday Just Around the Corner?

Content archive

  • The Four Hundred
  • Four Hundred Stuff
  • Four Hundred Guru

Recent Posts

  • Public Preview For Watson Code Assistant for i Available Soon
  • COMMON Youth Movement Continues at POWERUp 2025
  • IBM Preserves Memory Investments Across Power10 And Power11
  • Eradani Uses AI For New EDI And API Service
  • Picking Apart IBM’s $150 Billion In US Manufacturing And R&D
  • FAX/400 And CICS For i Are Dead. What Will IBM Kill Next?
  • Fresche Overhauls X-Analysis With Web UI, AI Smarts
  • Is It Time To Add The Rust Programming Language To IBM i?
  • Is IBM Going To Raise Prices On Power10 Expert Care?
  • IBM i PTF Guide, Volume 27, Number 20

Subscribe

To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

Pages

  • About Us
  • Contact
  • Contributors
  • Four Hundred Monitor
  • IBM i PTF Guide
  • Media Kit
  • Subscribe

Search

Copyright © 2025 IT Jungle