RE: [logs] Appliancebased Logging

From: Robert van den Breemen (rvdbreemenat_private)
Date: Mon Mar 17 2003 - 10:46:51 PST

  • Next message: Héroux, Christian: "[logs] How to forward syslog message to a central syslog server using snort"

    Dear Chris,
    Thanks for responding... Can you give me some insight on what you mean with
    "flakey"? Can you share with us what the conclusion of evaluation of
    commercial log analysis products was? 
    Thanks,
    Robert
    
    -----Original Message-----
    From: durnieat_private [mailto:durnieat_private] 
    Sent: maandag 17 maart 2003 19:26
    To: loganalysisat_private; rvdbreemenat_private
    Subject: Re: [logs] Appliancebased Logging
    
    
    
    -----BEGIN PGP SIGNED MESSAGE-----
    
    I went through a pretty thorough evaluation of commercial log analysis and
    event correlation software last November. Network Intelligence brought me an
    appliance to try out or a month or so. Unfortunately, the sotware never
    really performed up to our technical standards as far as device support
    goes. They cover alot of the major vendors though. It's not a bad box, just
    a bit flakey sometimes...
    
    Chris Kirschke, CISSP
    Silicon Valley Bank
    
    On Fri, 14 Mar 2003 22:26:56 -0800 Robert van den Breemen
    <rvdbreemenat_private> wrote:
    >Hi everyone,
    >Yesterday I had a presentation by Network Intelligence Corparation
    >(http://www.network-intelligence.com) of their product suite. I was
    >wondering if anyone on this list can share their experiences with
    >this
    >productline. It seems to be quite a total solution for implementing
    >a
    >logging infrastructure, including reporting & event correlation...
    >
    >Product is called: Envision.
    >The appliance seems to have a high sustaioned performance of up to 6000
    >events per seconds (loglines per second)...
    >
    >Anyone any experience, it seems to be a company that focussed on the 
    >states. Greetings,
    >Robert
    >
    >PS. Other products in their shop are: private I for example, which 
    >ships with PIX I think.
    >
    >--
    >      _///_
    >     /(@ @)\
    >==o00o=(_)=o0oo==[ Robert van den Breemen ]====
    >
    >
    >
    >
    -----BEGIN PGP SIGNATURE-----
    Version: Hush 2.2 (Java)
    Note: This signature can be verified at https://www.hushtools.com/verify
    
    wlsEARECABsFAj52EtgUHGR1cm5pZUBodXNobWFpbC5jb20ACgkQ3UH5NRolsbYPxQCg
    ixVDm21YH1h0DP5pUID9FQ05kacAoI11m4z4l3QfTQHkc3H+7ERVb0g5
    =voXq
    -----END PGP SIGNATURE-----
    
    
    
    _______________________________________________
    LogAnalysis mailing list
    LogAnalysisat_private
    http://lists.shmoo.com/mailman/listinfo/loganalysis
    



    This archive was generated by hypermail 2b30 : Mon Mar 17 2003 - 13:14:16 PST