Network Computing is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them. Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

AlienVault Unified SIEM Bundles Security Tools For MSPs And Enterprises: Page 2 of 2

"We were not able to analyze traffic at even 50 or 100 events per second," he says. He began migrating to the enterprise-grade Unified SIEM, which he says can analyze 10,000 to 15,000 events per second and enabled him to collect and store heavy log volume.

Unified SIEM has three components: the OSSIM-based SIEM, Sensor and Logger. The Sensor collects logs, event and flow data from network and security devices, as well as from applications. The Sensor can also provide asset discovery and identification, vulnerability assessment scanning using either Nessus or OpenVAS, and intrusion detection system (IDS) capabilities. It can even act as a wireless IDS to detect attack traffic and rogue access points.

The Logger provides high-performance encrypted transport of log data, forensic audit and analysis tools, and "military grade" data destruction. The SIEM provides numerous audit and compliance reports, as well as a reporting wizard for customization.

"The subscription provides a lot of reports and more effective correlation rules out of the box,'" he says, "which is important because we don't have a lot of people to help us." Cao says bundled VA and IDS capabilities save the city money that would otherwise be spent on additional products.

See more on this topic by subscribing to Network Computing Pro Reports Security: Wicked Innovation (subscription required).