Information system and network security with event log monitoring

Many companies mistakenly assume that unauthorized access is an external threat only. The majority of corporate security threats actually stem from internal sources, against which a firewall offers no protection.

A good security strategy includes real-time monitoring for critical security events and periodic analysis of your systems' security logs so that you can detect and respond quickly to attack. In fact, when reviewing the general controls of a corporation, public auditors and regulatory agencies define security log monitoring as a necessary best practice and a part of performing due diligence.

To monitor event logs effectively, you need an automated way to back up and clear the event logs network-wide and to archive them in a central database. This archiving needs to be done with some intelligence, noise has to be removed and a sensible description added. Without doing this, you will suffer from the following limitations:

  • No real time monitoring and notification of critical events
  • Cryptic event descriptions: Certain events that indicate suspicious activity have less than obvious descriptions
  • No long term archive

Windows NT/2000/XP/2003 logs a large ratio of unimportant events, such as workstations polling a domain controller for Group Policy updates. This makes analysis of the data without prior archiving and cleaning difficult to impossible.

Security incidents result in loss of operations, business, customers and revenue. Recovery is often a time consuming and expensive process. GFI EventsManager™ offers a 24/7 real-time intrusion detection and alerting system and an early warning signal to enable intrusion countermeasures. It also provides extensive rules to detect insider attacks.

GFI EventsManager™ to monitor your network for security breaches

  • Identify event patterns and pre-empt insider attacks through the powerful GFI EventsManager rules database
  • Real-time alerts can detect, alert you, and help you to avoid network security attacks
  • Reduce the risk to business continuity by pro-active measure
  • Increase productivity reduce manpower wasted in manual log management
  • Reduce administrative, financial and technical overhead required to manage, archive and convert apparently meaningless event logs to significant security reports for management

Next steps

Awards and reviews

Previous Next
    • Preferred Product’ award for GFI EventsManager
      RED_ReadrsChoice11_PP

      Preferred Product’ award for GFI EventsManager

      GFI EventsManager is named preferred product in th...

      RED_ReadrsChoice11_PP

      Preferred Product’ award for GFI EventsManager

      GFI EventsManager is named preferred product in the ‘best security auditing product’ category of Redmond Magazine’s Best of the Best Readers Choice Awards 2011.
      Redmond - December, 2011

    • HP Converged Infrastructure Ready Certification
      HP Converged Infrastructure Ready Certification

      HP Converged Infrastructure Ready Certification

      GFI Software, an HP alliance partner, has been cer...

      HP Converged Infrastructure Ready Certification

      HP Converged Infrastructure Ready Certification

      GFI Software, an HP alliance partner, has been certified HP Converged Infrastructure Ready - demonstrating GFI’s expertise in delivering solutions that are Converged Infrastructure compliant.

    • InfoWorld reviews GFI EventsManager
      Infoworld Logo

      InfoWorld reviews GFI EventsManager

      "GFI EventsManager Report Pack comes with dozens o...

      Infoworld Logo

      InfoWorld reviews GFI EventsManager

      "GFI EventsManager Report Pack comes with dozens of predefined reports (mostly Windows-related), each of which can be edited or used to make new reports." - InfoWorld

    • Editor’s Choice
      WinITPro_EditorsChoice.gif

      Editor’s Choice

      In a comparative review in of log management produ...

      WinITPro_EditorsChoice.gif

      Editor’s Choice

      In a comparative review in of log management products in WindowsIT Pro, the magazine gives GFI EventsManager 4.5 marks out of 5 for both its ease of implementation and ease of use. The reviewer recommends GFI EventsManager for anyone “whose log management needs are limited to Windows Events logs, syslog output and W3C log file information”. - Windows IT Pro