

Assuria Log Manager (ALM) has achieved CESG CCTM approval and securely collects and manages audit logs to comply with regulations. The small footprint ALM agents are available for Windows, UNIX and Linux servers, databases, applications, network devices, firewalls, routers, access control systems and many more. Collection from new log sources can be added via agent plug-ins. Collected logs are stored in their original format in a standard file / folder structure with log data integrity ensured through digital signatures and cryptographic hashes.
Operating systems, system software and applications have for many years had features to write audit logs to record events, data or actions taken. The benefits of using log data are well known to IT professionals who have used the information contained in logs for diagnostics and to verify actions taken by software, often as the first steps in problem identification.
Today such audit logs have attained a much higher level of importance; this is driven by several factors including policy compliance requirements. Organisations of all sizes and in both the public and private sector are increasingly required to be in compliance with an increasing number of legislative and industry regulations and standards. The requirements are driving organisations to seek tools to assist and automate their log management and compliance processes.
Uses for collected logs and log data can vary from near real-time collection and in-memory correlation of network traffic, through near real-time alerting / host based intrusion detection, regulatory compliance reporting, problem identification and resolution to incident response and forensic analysis.
X VirusnX SpywarenX SpamnX Web/IMnX IPS/Patch Mgmtn5 Data/System Mgmtn
Assuria Log Manager is a modular system and can be configured in a number of ways in order to meet user requirements for high availability and / or resilience of volume / capacity.
Multiple collectors can be configured and agents configured so that they can use whichever Collector is available with Load Balancing.
The Store and Database can, where required, be replicated using replication functionality native to the store or database. If required multiple agents can be installed on a single log source system though each agent must handle its own unique set of logs.
Just simply looking at a list of the type of logs that can be supported by ALM, there is a wide range of log sources that are supported out of the box, including those listed below (note - this is just a sample list - please contact Assuria for the full list of supported log sources):
| AIX Audit Log | Kiwi syslog server | ODBC (i.e. SQL Db Query) |
| Apache Web Server | Linux Daemon | Oracle Directory Server - Audit Logs |
| AppGate | McAfee ePolicy Orchestrator | Palo-Alto |
| Barracuda | McAfee NSM | RHEL Audit Log |
| Bloxx | MS Windows .EVT | Solaris BSM Logs |
| CheckPoint | MS Windows .EVTX logs | SDEE |
| Cisco IOS | MS SQL Server Error Log | SNMP Trap / Inform receiver |
| Cisco ASA | MS SQL Server Audit Log | Sophos |
| Cisco CIDEE | MS DNS Server Debug Logs | Sourcefire eStreamer |
| Cisco PIX Syslog Server | MS IIS 5 | Sourcefire JDBC |
| ClearSwift Email (29 different logs) | MS IIS 6 | SuSE SLES Audit Log |
| ClearSwift Web (54 different logs) | MS IIS 7 | Symantec Netbackup |
| DHCP | MS IIS 7.5 | Symantec Endpoint Protection |
| Encrypted Web Traffic | MS IAS | Unix Daemon |
| HP-UX Audit Log | MS SharePoint | Unix/Linux Syslog |
| IBM DB2 | MS Exchange Server | Verint Ultra (call centre logs) |
| IBM Websphere | NetFlow | VMware ESX |
| JIRA Access Logs | OPSEC LEA | VMware ESXi |
| Juniper | Oracle Directory Server - Access Logs | |
| Juniper Syslog Server | Oracle Directory Server - Error Logs |
Please note that the list of supported log types is growing rapidly through new customer implementations, so please ask for the latest list. However, ALM's architecture also means that almost any log type can be fully supported, even custom application logs, so please let us know what your log management needs are!
Assuria have created a whitepaper that outlines the significant drawbacks to using syslog due to it's lack of data integrity both in it's format and protocol. The whitepaper explains how Assuria can help secure the original standards but highly recommends avoiding syslog if possible in favour of the vendors own log mechanisms.
Download In Syslog we trust Whitepaper
Requirement 10 Track and monitor all access to network resources and cardholder data
GCSX No 13 Protective Monitoring
Uses for log data in addition to regulatory compliance include:
Today’s operating systems, applications and network devices, including Windows and LINUX / UNIX, can produce vast amounts of audit data within their logs. There are few tools available today to provide for reliable management of this log data.
© Copyright Castleforce 2007-2012. Web design by Theme Group