All the logging and security event monitoring tools offer some way to collect logs. Most every device or data source generates logs. Not all logs are worth collecting or storing for the purpose of security or compliance. So the first thing is that Intellitactics SIEM solutions provide optimal protocals for log collection.
Second, the SIEM solutions parse and normalize all the logs. Raw logs are important to keep - but parsed and normalized logs are critical to understanding and really important for advanced capabilities like correlation, reporting and notification.
Parsed logs are often referred to as security events. And, like logs, not all security events are "created equal". Security events can be aggregated to make the sheer number of them easier to deal with. But more important is that your SIEM solution should have the ability to prioritize the sensitive or ciritical security events. This means that the SIEM solution should package the analytics to support correlation and some level of analysis - there just aren't enough eyes to look at every log or every event.
Intellitactics packages the analytics for making sure you have the logs and security events that are critical for prioritizing these security events as ALERTS. Even if you don't have deep knowledge of the logs for a specific device - like a proxy server or an IDS - the Intellitactics SIEM provides an analytics module for them - and there are many of them packaged with every one of our SIEM solutions.
Today we're recognizing David Empringham and his team of device experts. Dave and his team develop and update data modules and analytics modules for secuirty devices and even custom, one of kind applications. This means that Intellitactics SIEM solutions have no limitations - you can manage as many of them as you want. If it generates logs, Dave's team ensures that the logs can be collected. THANKS and GREAT WORK to DAVE and The REST OF YOUR TEAM!!!
Ask DAVE about any devices or data sources by commenting HERE!