NNT Log Tracker Enterprise™
Comprehensive and easy-to-use Security Information and Event Management (SIEM) solution for any compliance mandate providing
- Enterprise-class SIEM capabilities
- Compliance Automation
- User and System Activity Audit trails
- Network Anomaly forensics
- Proactive Threat Detection
Log Analysis or SIEM, is a key weapon in the fight against any cyber-attack. By gathering logs from all devices including network devices, Unix and Windows servers, applications and databases, and analyzing them for unusual or suspicious activity, the method and source of any attack can be identified, enabling preventative measures to be continually improved.
This is why all security policies place log retention at their core. PCI DSS compliance for example, requires logs to be gathered and reviewed daily, and retained for at least one year, but all other compliance standards mandate the use of SIEM technology to detect and forensically investigate security incidents: “capture”, “monitor”, “review”, and “retain” log data.
Security Information and Event Management (SIEM) technology has revolutionized the use of log analysis as a means of identifying the clues and pointers indicating a hacker activity to provide a powerful cyber defense system.
NNT Log Tracker Enterprise has built-in support for all major GRC standards, protecting customer data and customer privacy to auditor-ready levels right out of the box, including
Compliance Standards Supported
- PCI DSS V3.2
- NIST 800-53
- DISA STIG
- NERC CIP and NRC RG
- DODI Defense Cybersecurity Program
Platforms and Applications Supported
- Network devices, including Cisco, Juniper, Nortel, Avaya, Huawei, Dell
- All Windows, Unix and Linux servers, including Solaris, RHEL, SUSE, Ubuntu, CentOS, HP/UX, AIX and Non Stop
- Firewall or IPS and IDS devices, including Checkpoint, Cisco ASA, Palo Alto, Fortinet, WatchGuard and SonicWall
- Database and Data Warehouses servers including SQL Server, Oracle, DB2, MySQL, PostgreSQL, Hadoop, Netezza, Informix, and Teradata
- Middleware and Web servers including JBOSS, Fusion, WebSphere, IIS, Apache, Tomcat, JBoss, HIS, Websphere, SunOne and Weblogic
- SCADA, HMI, MES and other industrial control systems, including Schneider Electric, GE and Siemens
- IBM Mainframes and IBM AS/400-iSeries, for user activity and file integrity monitoring
- All other potentially useful sources of log information such as door entry systems, environmental sensors
NNT Log Tracker Enterprise™ doesn’t stop there. All event logs are analyzed and correlated automatically, applying a comprehensive series of rules pertinent to any Security or Governance policy. Any breach of compliance will be alerted immediately allowing pre-emptive action to be taken before a problem arises. Pre-defined rules templates allow you to be in control of compliance, straight out-of-the box. And of course, even subtle hacker activity will be highlighted in real-time using Log Tracker SIEM threat detection rules.
NNT’s complete solution for all Security Information and Event Management (SIEM) requirements provides:-
Support for all Security and Governance policies, via pre-packed Compliance Rule Templates
Real-time security warnings i.e. Attempted Brute Force Attack
PCI DSS, SOX, NIST 800-53, DISA STIG, HIPAA, NERC CIP and NRC RG, DODI Defense Cybersecurity Program
COBIT of Connection support ‘out of the box’
Web-based dashboard and integration with Servicedesk as standard
Powerful, keyword-based Event Log mining across any combination of devices and applications
Easy to expand coverage and storage
Log Tracker Enterprise™ allows you to focus on true exceptions and important events by masking off the sometimes overwhelming flood of logs. The pre-built Compliance Templates can be used to build your own keyword and logic-based correlation rules, allowing you to manage what really matters to your organization from a security and compliance standpoint.
Key features of NNT Log Tracker SIEM solutions versus the competition:-
- 100% software-based solution provides a much less restrictive solution than fixed-form appliances from LogRhythm and McAfee
- Easy to expand capacity via VM resource without rigid events per seconds (EPS) licensing used by most other SIEM appliances such as QRadar and ArcSight
- Larger scale requirements catered for using multiple distributed Event Collectors and Servers much more flexible and less expensive than appliance-based solutions
- No limit on daily license or indexing capacity unlike comparable solutions from Splunk which cost more anytime the basic Gigabyte allowance is exceeded
- No hidden or extra costs for different device types, Manufacturers or Databases to be covered
- Where a managed SIEM service or outsourced PCI Compliance Service is preferred, NNT can offer our NNT Security Event Analysis Service, providing a comparable service to that offered by the likes of Trustwave and Dell SecureWorks
Plus all the benefits of NNT Change Tracker's non-stop, continuous vulnerability management and real-time, enterprise-class file integrity monitoring to give an unrivaled security and compliance solution.