Review: Appliances boost log management

LogLogic 4 allows real-time analysis of data logs to aid compliance and risk mitigation

Written by Dave Bailey

Larger Image

LogLogic’s turnkey appliance-based system for the capture and processing of log data should appeal to any enterprise that is required to demonstrate compliance with corporate governance regulations such as Sarbanes-Oxley and the Payment Card Industry (PCI) Data Security Standard.

The LogLogic appliances we reviewed were from the high end of the firm’s two product families. The LX Series 2010 appliance performed real-time log collection and analysis functions, while the ST Series 3010 system that we daisy-chained to the LX2010 automated the archiving of the logs, applying certificated timestamps to protect them against tampering.

After attaching the two appliances to IT Week Labs network, both the LX2010 and ST3010 were loaded with eight Seagate Barracuda serial ATA (Sata) hard disks and two power supply modules. The appliances were ready to run after disk synchronisation, which took between 10 and 15 minutes.

Both appliances are 2U high and use AMD 2.4GHz dual-core Opteron processors. Due to its role as the archival and log forensics appliance, the ST3010 has 2GB of memory and 4TB of storage ­ twice that of the log-collecting LX2010 appliance. The LX2010’s 2TB of disk storage is set up as Raid 1+0, while the 4TB used by the ST3010 is configured as Raid 5+1, which maximises both fault-tolerance and availability.

We managed the initial setup through a standard serial console. After we had got the LX2010 to autodiscover our IT assets and set up both appliances to access an NTP server, we were able to continue managing the appliance using either a web browser from our Windows Server 2003 system, or a free Telnet/SSH client such as Putty.
To make our test as realistic as possible, we set up a script to populate the appliances with significantly more log data than would normally be generated by IT Week Labs network infrastructure.

Interface
The LX2010’s web interface is divided into two sections. The upper section holds the dashboards, real- time log data views and alerts, together with all the reporting options, while the lower section holds the administration and maintenance features.
The top half of the interface has eight tabs down the side, which drill down into numerous sub-tabs. The main tabs are: Dashboards, Real-Time Viewer, Search, Alerts, Custom Reports, Real-Time Reports, Summary Reports and Preferences.

Clicking on the Management Station dashboard brings up a graph of the number of log messages processed by the LX2010 over time, and also the number of messages processed per second, which could allow IT managers to see any abnormal log activity. Any outstanding alerts and a table of messages skipped, unapproved, truncated or dropped can also be seen.

The System Status dashboard gives a graph of CPU and disk usage, while the Log Source Status dashboard can be used to check what systems have been found and are currently generating log data to be processed by the appliance. We could see, for example, Microsoft Exchange and Microsoft Internet Security for Acceleration servers, Juniper firewalls and Cisco VPN 3000 concentrators.

The LogLogic appliances were also there, and administrators accessing the appliances to create reports or schedule alerts also have all their activity and interactions with the appliances logged.

The Real-Time Viewer lets users see log data as it is actually processed by the appliances. Users can also choose to customise the Viewer to show specific logs. For instance, we could define what type of device we wanted to see logs from, such as Cisco Pix firewalls. Or we could choose to look for a pre-defined log message, such as “Microsoft DNS: Critical Errors”. We could choose an exact phrase occurring in a log message or use Boolean logic to pull out specific log messages.

LogLogic’s Search tab can be used to automatically produce a report on network connection attempts over any user-defined timescale. We produced a report detailing connection attempts through a Juniper NetScreen firewall and exported it as a comma-separated value (CSV) list. Advanced options also allow users to define what type of data, such as source IP address, destination IP address and port number, appears on the list. Boolean logic can also be applied to further enhance the search, and the search configuration can be saved as a custom report.

The alerting features can be configured to flag up a wide variety of potential problems. For example, admins can set up the system to send out alerts when server disk usage is over 80 per cent, or when changes have been made to switch configurations, or even when users are writing data to CDs.

Reporting options
The reporting options are also comprehensive, and there are many report templates available. Users can also define their own custom reports and schedule these to run
at hourly, daily, weekly or monthly intervals. The resulting report
can then be emailed as a CSV, HTML or a PDF file.

In conclusion, LogLogic’s system has a wealth of features that should allow enterprises to get on top of any regulatory compliance obligations they need to meet. It was easy to use the pre-defined report templates and also to create customised reports. It was also easy to define specific alerts to notify security or general IT personnel about critical conditions in enterprise network and IT infrastructure.

On top of the cost of the appliances, enterprises face separate charges for LogLogic’s pre-defined compliance monitoring and reporting packages. These cover a range of governance topics, including Sarbanes-Oxley, Itil and the PCI data security standard, and cost £7,500 + VAT each.

LogLogic offers a range of support services, including 24x7 cover and user training.

Tags:

Product overview

  • Price: £80,000 (for ST 3010 plus LX 2010 appliances)
  • Web site: LogLogic

Ratings

  • Our rating: 5
  • Average user rating:

Verdict

LogLogic's appliance-based system can be used to collect, alert on, store and report on system logs taken from enterprise network and IT infrastructure. It can be up and running in 15 minutes and although the system appears complex to manage, the workflow is well thought out and logical.

Pros: Easy to set up; comprehensive feature set.

Cons: Expensive; compliance reporting packages extra.

Best prices

reader comments

related articles

padlock

Updated: ICO offers advice to businesses handling data

Government watchdog to release handbook for dealing with data 11 Dec 2007

 

Firms woken up by HMRC breach, says ICO

Data watchdog, the Information Commissioner, says that the HMRC breach could have a positive outcome 05 Dec 2007

Sarbanes Oxley compliance becoming easier

Firms are improving their Sarbanes Oxley compliance activities 28 Nov 2007

today's top stories

CIOs must embrace collaboration tools

Author Don Tapscott gives Angelica Mari his reasons for promoting social networking tools and says transparency is the key to security 04 Dec 2008

On a quest to build a connected society

BT Design’s JP Rangaswami talks to Gareth Morgan about his pivotal role in the telecoms giant’s efforts to deliver universal broadband and his plans to tap into the creativity of the open source community 04 Dec 2008

IT leaders must stand by India

A sense of perspective is the most important response from IT leaders to the attacks in Mumbai 04 Dec 2008

Case study: Clifford Chance

Law firm implements Sun platform and reduces datacentres to gain efficiency and cost synergies 03 Dec 2008

Should CRM be more sociable?

As vendors rush to add more social networking bells and whistles to their CRM products, some experts warn that users must tread carefully when venturing into online communities 03 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Doctors looking at a computerAnalysis

Watchdog wants IT to cure privacy woes

Information Commissioner Richard Thomas is urging organisations to put privacy protection at the top of their procurement and development criteria 04 Dec 2008

Colin McDonaldComment

Web 2.0 has potential to transform staff training

Employees can sharpen their IT skills through using the latest interactive training tools, writes Colin McDonald 04 Dec 2008

Advertisement

Primary Navigation