Upcoming Events

Cloud Connect
Santa Clara
Feb 13-16, 2012

Cloud Connect brings together the entire cloud eco-system to better understand the transformation we're experiencing and promises to be the defining event of the cloud computing industry. Learn about the latest cloud technologies and platforms from thought leaders in Cloud Connect’s comprehensive conference.

Register Now!

More Events »

Subscribe to Newsletter

  • Keep up with all of the latest news and analysis on the fast-moving IT industry with Network Computing newsletters.
Sign Up

Email Email  Print  Share


Log Management Gets SLIM

Tags: , , , , , , , , , , , , , , , , , , , , , , , , , , , , ,

Channel: Other, Networking & Mgmt, Servers & Storage, Data Protection, WAN & App Acceleration

The Upshot

Claim
Q1 Labs' Simple Log and Information Management (SLIM) product adds event correlation to log management. It provides reports based on log data. The company says the product can help meet regulatory requirements that demand log retention and review.
Context
Q1 Labs is a security event management (SEM) company that's getting into the log management market with SLIM. Meanwhile, log management vendors such as Splunk and LogLogic are adding data mining features to their products. SLIM is best suited to correlation and reporting rather than data mining.
Credibility
SLIM uses the same underlying framework used by that Q1 Labs' SEM product, QRadar. The event correlation and report definitions are easy to set up. Defining parsing rules for messages can be difficult, but is on par with other log management products.

QRADAR SLIM

Log management is a regulatory requirement and best practice. It has grown from simple aggregation and storage of logs to become another data resource that can be mined, trended and reported on.

Q1 Labs' Simple Log and Information Management—SLIM—platform stores logs from a variety of devices and can correlate events and create ad hoc and scheduled reports. The appliance is rated for 5,000 events per second; adding more devices increases this events-per-second ratio.

SLIM's event correlation feature can be useful for uncovering malicious or unwanted activity in real time and can be easily customized. It also includes report templates for regulations such as Sarbanes-Oxley and GLB. However, SLIM is not as agile with real-time data mining or arbitrary event data compared with products from Splunk or LogLogic, both of which create indexes of data as they stream from event sources. SLIM is a good fit for companies that want to automate report generation and event correlation from log data.

As tested, SLIM costs $24,000; the product ships with 2 terabytes of disk space, and raw data and indexes are compressed after two days, conserving space with minimal impact on searching. Splunk's commercial software starts at $5,000 for 500 MB of indexed data per day, and hardware typically runs to over $10,000 for a beefy server. Moreover, Splunk doesn't have SLIM's event correlation component. A more comparable product, LogLogic's LX 2010, lists for $28,000 plus an additional $14,999 for compliance and control suites. It has more robust archiving functions and powerful search capabilities.


Page:  1 | 2 |3 |4 |Next Page »

Related Reading


More servers-storage Insights



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Network Computing encourages readers to engage in spirited, healthy debate, including taking us to task. However, Network Computing moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Network Computing further reserves the right to disable the profile of any commenter participating in said activities.

 
Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
 

Research and Reports

Hypervisor Derby
August 2011

Network Computing: August 2011

TechWeb Careers