System Log Management Vendors

Talisker's summary of Security Event Correlation products

   
Addamark [From the web site] Addamark Technologies offers the Log Management System (LMS), a scalable software solution for managing high volume log data. LMS delivers unprecedented scalability, performance, efficiency and ease-of-use
Adiscon Provides a variety of tools focused on monitoring Microsoft Windows hosts and applications, and integrating Windows monitoring into a traditional syslog infrastructure.
e-Security

[From the web site] e-Security is the leading provider of Security Event Management software. The e- Security Management System aggregates, standardizes, analyzes and reports security event information from any source across the enterprise in a centralized console in real-time. This information is then correlated with the Symantec SecurityFocus Vulnerability Database, the most comprehensive database of known threats, to deliver insight into vulnerabilities, expert advice, and recommended steps toward remediation.

eIQNetworks [From Mark Snellgrove] I evaluated their SyslogAnalyzer 2.0. When it comes out, their 3.0 version will do most of what we need. We plan to use it to consolidate Windows and Unix logs without having to deploy agents. It has some "canned" reports that may also prove useful. They also have a product to analyze Firewall logs.
GFI LANguard Security Event Log monitor


Performs intrusion detection and network security reporting by monitoring the security event logs of all Windows 2000/NT servers and workstations. Alerts you in real time about possible intrusions/attacks.



IBM Tivoli Risk Manager [From Bennett Todd] This is a product where you make provisions to route all your log data into a central analytic server, and it then tries to classify and prioritize the records, and do some "correlation", by which they mean producing events that reflect collections of other events that have been logged.
NUXSL Network Unix Shell Logger [From the web site] nuxsl is a distributed, muti tier, client server communication tool which enables you to centralize your auditing of user shell accounts under a broad wide range of unix computing environments.
TNT's ELM Log Manager [From the web site] ELM Log Manager™ 3.0 gives system and security administrators the power to see all event log entries with unrivaled clarity. ELM Log Manager provides event log monitoring and collection, file system log file monitoring, integrated SNMP Trap and Object ID support, TCP and UDP Syslog receivers, a rich notification engine, and built-in reporting for Windows NT, Windows 2000, Windows XP, and TCP/IP- based systems and devices.
   

Please contact us if you wish to request we add a link.