• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • Pat Townsend Normalizes i5/OS Log Data for Security Analyses

    October 9, 2007 Alex Woodie

    There are many advantages to using a System i server to run business applications, including high degrees of security, scalability, and reliability. But there are also disadvantages to the proprietary platform, such as the fact that its security log data is incompatible with industry standard formats used by Windows, Unix, and Linux machines, which poses a challenge to security event correlation. Last week, i5/OS software vendor Patrick Townsend & Associates launched a new product, called the Alliance LogAgent, that transforms i5/OS log data into the industry standard “syslog” format.

    It used to be that nobody paid much attention to the various computer logs and audit journals that document the day-to-day processes of a business machine. They existed mostly in the background, storing tons of raw data only the most die-hard geeks could understand, let alone derive benefit from.

    But now, we’re in the midst of a security log renaissance. Regulations such as PCI, SOX, and HIPAA are leading companies to delve into their server logs like never before, determined to find evidence of a hacking ring, confirmation of organized crime, or traces of unauthorized internal access–or just to get the auditors off their backs. Equipped with advanced security information and event management (SIEM) systems, forensic investigators and chief security officers rely on the raw data provided by logs to bring down the bad guys. There’s almost something sexy about security logs.

    And while a System i server is less likely to be hacked than your average Linux or Windows box, the platform hasn’t been participating in the security log revolution to the same extent as its “open systems” brethren. The reason for this is that, while the rest of the computing world has largely agreed to use the syslog protocol, IBM has steadfastly maintained its own proprietary log data format for the i5/OS server.

    With Alliance LogAgent, Pat Townsend is addressing the System i’s separation from the SIEM marketplace and the capability of SIEM products to correlate the security data from all IT assets–including servers, databases, and network devices–thereby boosting overall security. The product does this by translating data collected from the i5/OS logs, such as the QAUDJRN and QSYSOPR journals, as well as application messages and SNMP traps, into the RFC 3164 protocol, which is the standard format used by major SIEM products, according to Pat Townsend.

    The software also digs up and translates critical System i security data that may be missed if the QAUDJRN journal is the only place you look. Because several popular open-source applications for the System i–such as the Apache Web server, the MySQL database, and applications written in PHP–store their log data on the IFS, it can be easily overlooked. Integration with other Pat Townsend network products, including Alliance FTP Manager, Alliance XML/400, and Alliance AS2 Integrator, provides more grist for the SIEM security data mill.

    Once translated to RFC 3164 format, i5/OS security event information can be shared with many cross-platform SIEM systems that use the syslog standard, including the open source Syslogd application that’s available for Unix and Linux, and several commercial offerings, including ArcSight‘s ESM, Symantec SIM, LogLogic‘s LX, Novell‘s Sentinel, Q1Labs‘ QRadar, TriGeo‘s SIM, and CrossTec‘s Activeworx, Pat Townsend says. These products provide benefits in the area of real-time alerting, as well as after-the-fact reporting.

    The product also comes with tools that allow users to define their own System i security events, and interfaces for integrating Alliance LogAgent routines into ILE applications. With this latter capability, Pat Townsend expects the product to be a good seller among ISVs.

    Alliance LogAgent is largely based on the open source Syslogd application sold and supported by BalaBit. Pat Townsend ported it to run on the System i, and provided the i5/OS know-how to make the product really fit into this peculiar platform.

    In addition to gaining a more complete picture of one’s security posture, Alliance LogAgent can also help free up gigabytes of valuable disk space on the System i, providing a cost savings. Users can cut down on their bandwidth requirements by filtering the events sent to the SIEM, while offloading archive log data onto cheaper Windows and Linux servers can bring additional savings.

    Pat Townsend, president of the Olympia, Washington, company, says the effectiveness of log analysis and management software depends on the capability to consolidate all security and event data into one place. “Only then can patterns be analyzed for potential security breaches,” he says. “By providing a System i log agent and integrating all of our encryption and data security solutions into the logging architecture, our customers get unmatched support for security monitoring.”

    Alliance LogAgent is available now. The product requires OS/400 V5R1 or higher. For more information, visit www.patownsend.com.

    RELATED STORIES

    Patrick Townsend Brings 256-Bit AES Encryption to DB2/400 Data

    Pat Townsend Teams with iSoft for Native OS/400 AS2 EDI-INT Software

    PowerTech to Resell 256-Bit Encryption from Pat Townsend



                         Post this story to del.icio.us
                   Post this story to Digg
        Post this story to Slashdot

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Tags:

    Sponsored by
    DRV Tech

    Get More Out of Your IBM i

    With soaring costs, operational data is more critical than ever. IBM shops need faster, easier ways to distribute IBM applications-based data to users more efficiently, no matter where they are.

    The Problem:

    For Users, IBM Data Can Be Difficult to Get To

    IBM Applications generate reports as spooled files, originally designed to be printed. Often those reports are packed together with so much data it makes them difficult to read. Add to that hardcopy is a pain to distribute. User-friendly formats like Excel and PDF are better, offering sorting, searching, and easy portability but getting IBM reports into these formats can be tricky without the right tools.

    The Solution:

    IBM i Reports can easily be converted to easy to read and share formats like Excel and PDF and Delivered by Email

    Converting IBM i, iSeries, and AS400 reports into Excel and PDF is now a lot easier with SpoolFlex software by DRV Tech.  If you or your users are still doing this manually, think how much time is wasted dragging and reformatting to make a report readable. How much time would be saved if they were automatically formatted correctly and delivered to one or multiple recipients.

    SpoolFlex converts spooled files to Excel and PDF, automatically emailing them, and saving copies to network shared folders. SpoolFlex converts complex reports to Excel, removing unwanted headers, splitting large reports out for individual recipients, and delivering to users whether they are at the office or working from home.

    Watch our 2-minute video and see DRV’s powerful SpoolFlex software can solve your file conversion challenges.

    Watch Video

    DRV Tech

    www.drvtech.com

    866.378.3366

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Sponsored Links

    SafeData:  The iSeries HA Solution that’s Guaranteed
    COMMON:  Join us at the annual 2008 conference, March 30 - April 3, in Nashville, Tennessee
    NowWhatJobs.net:  NowWhatJobs.net is the resource for job transitions after age 40

    IT Jungle Store Top Book Picks

    The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
    The System i Pocket RPG & RPG IV Guide: List Price, $69.95
    The iSeries Pocket Database Guide: List Price, $59.00
    The iSeries Pocket Developers' Guide: List Price, $59.00
    The iSeries Pocket SQL Guide: List Price, $59.00
    The iSeries Pocket Query Guide: List Price, $49.00
    The iSeries Pocket WebFacing Primer: List Price, $39.00
    Migrating to WebSphere Express for iSeries: List Price, $49.00
    iSeries Express Web Implementer's Guide: List Price, $59.00
    Getting Started with WebSphere Development Studio for iSeries: List Price, $79.95
    Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
    Getting Started with WebSphere Express for iSeries: List Price, $49.00
    WebFacing Application Design and Development Guide: List Price, $55.00
    Can the AS/400 Survive IBM?: List Price, $49.00
    The All-Everything Machine: List Price, $29.95
    Chip Wars: List Price, $29.95

    What Are Else Are Employees Up To? Shopping Online During Con Calls Controlling System i Shutdown Activities Using an Intelligent Power-Handling Program, Part I

    Leave a Reply Cancel reply

Volume 7, Number 38 -- October 9, 2007
THIS ISSUE SPONSORED BY:

BOSaNOVA
Aldon
nuBridges
Computer Measurement Group
RJS Software Systems

Table of Contents

  • ACOM Updates EZ Content Manager
  • looksoftware’s Modernization Suite Resembling a Full IDE
  • Pat Townsend Normalizes i5/OS Log Data for Security Analyses
  • Linoma Boosts Surveyor/400’s SQL Functionality
  • PowerTech Updates Compliance Manager
  • IBM Comments on iSeries Access and Windows Vista
  • Update on Virtualization Manager’s i5/OS LPAR Capabilities
  • Raz-Lee Supports SSL in i5/OS Firewall
  • Inventive Designers Launches DTM for iSeries Version 3
  • Optio Software Saves Manufacturer from the Paper Chase

Content archive

  • The Four Hundred
  • Four Hundred Stuff
  • Four Hundred Guru

Recent Posts

  • The Turning Point For Power Systems Is Here, And Now
  • How IBM i Users Can Compete In The Digital Era With Composable Commerce
  • IBM Streamlines Data Migration With New Partition Mirror Tech
  • Profound Logic Adds MCP To IBM i AI Tool
  • IBM i PTF Guide, Volume 27, Number 29
  • Power11 Entry Machines: The Power S1124 And Power L1124
  • BRMS Isn’t The Only Backup Product With A Security Problem
  • Guru: A Faster Way To Sign A JWT
  • Maxis Adds IBM i Support To Database Modernization Tool
  • IBM i PTF Guide, Volume 27, Number 28

Subscribe

To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

Pages

  • About Us
  • Contact
  • Contributors
  • Four Hundred Monitor
  • IBM i PTF Guide
  • Media Kit
  • Subscribe

Search

Copyright © 2025 IT Jungle