Information Security Blog

Log Consolidation or SIEM? (BOTH !!!!)

Security Information Event ManagementIn the “old days” (pre-2009)  there was a fundamental decision to make when implementing log management technology.  Do I go log consolidation (LogLogic, LogRythm, Splunk) or do I go Security Information Event Management (Arcsight, NetForensics, Sentinel)?  It really boiled down to whether or not you needed the increased capabilities of SIEM such as  real-time correlation, dynamic real time data normalization, and advanced integration with other core systems including Identity Management, Network Monitoring, Ticketing, CMDB, & Vulnerability/Configuration Management.

The world has changed. We are of the strong opinion that for most F500 class log management implementations it’s no longer SIEM OR Log Consolidator — its now SIEM AND Log Consolidator.

The reason is simple a growingly insane number of events that need to be captured. As compliance requirements relating to PCI, PII, PHI, et al drive the need for a greater and greater number of events to be captured, one of SIEM’s advantages (having a RDBMS as its back-end) can quickly become a disadvantage.  When data rates start to approach 5,000 events per second (which is definitely reachable in many environments) the challenges/limitations associated with getting data into and out of an RDBMS can become problematic:

  • Few DBAs have experience optimizing databases with these characteristics.
  • Database storage requirements (often on a very expensive SAN) can approach a Terabyte per day.
  • Recovering from a database issue (e.g., rebuilding a corrupted index) becomes very challenging and time consuming.

Leading vendors such as Arcsight and Novell (Sentinel) recognized this issue and have recently developed Log Consolidators that are intended to work seamlessly with their SIEMs so that you can enjoy a best of breed approach to log management/forensics/compliance.

Leveraging Log Consolidators at the “edge” (e.g., at various business units) simplifies the process of deploying a solution, provides a local searchable event repository, and reduces storage requirements by a factor of 10 (or more).  Only those events that require SIEM capabilities (say 20%) are forwarded to the SIEM in real-time to ensure that full SIEM functionality is retained while eliminating the pain associated with a 5,000 EPS RDBMS).

This approach really allows an organization to end up with the “best of both worlds”.



Is ISO 27001 Right for (Y)our Organization?

iso-27001-webinar

Thinking about ISO 27001 Certification? View our free On-Demand ISO 27001 Webinar

  • How to deal with increasing threats
  • How to manage multiple regulatory requirements
  • How to handle client requests for attestation
  • To validate that significant changes did not have unanticipated results

Free Download: A Best Practices Guide to Database Security

database security roadmap

Because data is only as secure as the systems & processes it relies on – a holistic approach to data security is essential. This roadmap is not meant to be exhaustive but rather to stimulate the necessary thought process to put you on the path to good data security.

Free Whitepaper: Stop Wasting Money on Penetration Testing

penetration-testing-whitepaper

Penetration Testing is most frequently performed to:

  • Substantiate the net effectiveness of a mature control environment
  • Prove to a third party that an environment is secure/trustworthy
  • Quickly assess the security of a less mature control environment (in a sense a technical risk assessment)
  • To validate that significant changes did not have unanticipated results

Free Download: ISO 27001 Implementation Roadmap

ISO 27001 RoadmapHave no fear – our “roadmap” will guide you, step by step, through the entire ISO 27001 process.

Getting to ISO 27001 certification is a process made up of things you already know – and things you may already be doing!

Free Whitepaper: Five Best Practices for SIEM

siem-whitepaper

The promise of SIEM is the consolidation of all relevant Security Event Logs from disparate sources into a single unified and normalized data store.

Download: Information Security Attestation Guide

Information Security GuideA Best-Practices Guide to Information Security Attestation

Download our proven Information Security Guide to simplify the process of protecting your data, proving you’re secure and growing your business.

Best Practices for Firing A Network Security Administrator

Firing A Network Security AdministratorWant to know how to fire a Network Admin? Need to know what precautions to take? Firing any employee can be a stressful event. Firing one who has significant knowledge of and privileged access to your Information Technology/Security infrastructure is even more stressful, as the risks are so notable.

About the Author:

John Verry, CISA, 27001 Certified Lead Auditor, CCSE, CRISC - "Security Sherpa" - Information Security Auditor

Add a Comment