<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
	>
<channel>
	<title>Comments on: How many devices reporting to your SIM / SEM?</title>
	<atom:link href="http://www.infosecpodcast.com/2006/08/how-many-devices-reporting-to-your-sim-sem/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.infosecpodcast.com/2006/08/how-many-devices-reporting-to-your-sim-sem/</link>
	<description>Information Security related news, opinions and ramblings</description>
	<lastBuildDate>Sat, 09 Jul 2011 16:32:24 -0400</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Christofer Hoff</title>
		<link>http://www.infosecpodcast.com/2006/08/how-many-devices-reporting-to-your-sim-sem/comment-page-1/#comment-35</link>
		<dc:creator>Christofer Hoff</dc:creator>
		<pubDate>Thu, 10 Aug 2006 01:29:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.infosecpodcast.com/security/2006/08/how-many-devices-reporting-to-your-sim-sem/#comment-35</guid>
		<description>Hi Chris... 
 
Recalling a past life, I implemented a mid-tier SEIM tool which I orginally deployed as a centralized log consolidation and archival platform which, over time, evolved with the vendor&#039;s software to a full-fledged SEIM solution. 
 
We had approximately 250+ Windows (NT, 2K, 2K3) servers, some linux and a 4 firewall clusters (Crossbeam, Nokia, Pix) and some IDP reporting via various conduits: LEA, Syslog, SNMP, and Windows Events.  This did not make up the entire enterprise, but rather things that provided critical control or were high-value assets. 
 
On average we hit over 3700 events per second with the bulk of the log entries coming from the rather noisy FW/IDP devices as well as the steady state Windows stuff. 
 
Yes, the reporting tended to be slow(er than we would have liked) and we began to look at other alternatives as they came to market such as SenSage and LogLogic for the archival and fast search capabilities. 
 
We used the dashboard for threshold notification (as realtime as it got for us) which triggered based upon device input and certain combinations/correlation of various abstracted/linked patterns indicating &quot;anomalous&quot; and potentially &quot;bad&quot; traffic. 
 
Chris </description>
		<content:encoded><![CDATA[<p>Hi Chris&#8230;</p>
<p>Recalling a past life, I implemented a mid-tier SEIM tool which I orginally deployed as a centralized log consolidation and archival platform which, over time, evolved with the vendor&#039;s software to a full-fledged SEIM solution.</p>
<p>We had approximately 250+ Windows (NT, 2K, 2K3) servers, some linux and a 4 firewall clusters (Crossbeam, Nokia, Pix) and some IDP reporting via various conduits: LEA, Syslog, SNMP, and Windows Events.  This did not make up the entire enterprise, but rather things that provided critical control or were high-value assets.</p>
<p>On average we hit over 3700 events per second with the bulk of the log entries coming from the rather noisy FW/IDP devices as well as the steady state Windows stuff.</p>
<p>Yes, the reporting tended to be slow(er than we would have liked) and we began to look at other alternatives as they came to market such as SenSage and LogLogic for the archival and fast search capabilities.</p>
<p>We used the dashboard for threshold notification (as realtime as it got for us) which triggered based upon device input and certain combinations/correlation of various abstracted/linked patterns indicating &quot;anomalous&quot; and potentially &quot;bad&quot; traffic.</p>
<p>Chris</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-35" src="http://www.infosecpodcast.com/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('35', 'add', 'www.infosecpodcast.com/wp-content/plugins/comment-rating/', '1_14_');" title="Thumbs up" /> <span id="karma-35-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-35" src="http://www.infosecpodcast.com/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('35', 'subtract', 'www.infosecpodcast.com/wp-content/plugins/comment-rating/', '1_14_')" title="Thumbs down" /> <span id="karma-35-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
</channel>
</rss>

