Saturday July 4, 2009 9:45 AM AEST
 
Latest Comments
"Agree that wireless hotspots are an easy way for hackers to gather information from connected ..."
by Patrick Hooper | Jul 3, 2009 4:06 AM
 
"Katarzyna what has this got to do with Symantec?? "
by PaulC | Jul 2, 2009 12:55 PM
 
"Hi Nadim, I'm the chief marketing officer at Ounce Labs, and I disagree with your statement. ..."
by Jennifer Sullivan | Jun 30, 2009 11:56 PM
 
"noobs!"
by webappsec | Jun 30, 2009 4:53 PM
 
"Jude makes a good point: by increasing the amount of false information provided to phishers, it ..."
by webappsec | Jun 30, 2009 4:43 PM
Web

LogRhythm v4.0

  • Email a Friend
  • Print Page
LogRhythm v4.0
Product Info
Supplier:
Product Rating
Features:  5
Ease of Use:  5
Performance:  5
Documentation:  5
Support:  5
Value for Money:  5
Overall Rating:  Overall Rating
 
For: One of the best network log analysis tools we've seen
Against: Nothing that we found
Verdict: Top-end network analysis tool. This gave our Best Buy a strong run for its money, but still we rate it Recommended
Related Articles
This is a serious log analysis tool. It covers all the bases you need to cover for network forensics. The appliance contains all the features you would expect in a SIEM solution, plus the ones you need for managing log evidence.
In a forensic environment you would save the raw logs in a chain of custody and perform all analysis on LogRhythm's archived data, never taking the chance of corrupting actual evidence.

The appliance is easy to set up and deploy. Since it is watching the network all the time in its role as a log correlator and analyser, it will have everything you need to perform network forensics.

It can take data from most types of logs found on a network. Plus, its Universal Database Log Adapter lets it gather logs from most types of database systems. This is a major forensic benefit.

One of LogRhythm's best features is the Log Miner. This function provides multiple, innovative ways to view log data from multiple sources. The displays tell a story very quickly, leading to drill-downs that access exactly what you are looking for. Newly improved handling of log metadata adds to the high performance.

LogRhythm provides good documentation to meet the needs of both administrators and end users. The product comes with all user, administrator and appliance manuals to make operations and deployment straightforward.

The administrator's guide contains deployment and management documentation as well as "how to" examples to assist users from start to finish. The documentation is well laid out and easy to follow, with good examples and script code.

Support offerings include web, email and phone assistance. LogRhythm also offers a support portal with specific resources to help customers troubleshoot problems. Other available services provided by LogRhythm are deployment and implementation planning, custom configuration, training and managed services.

Starting at US$20,000, this is a very good value, even if all you want it for is forensics. If you plan to implement the LogRhythm appliance as a full featured SIM, it’s an even better deal.

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Exclusive Data Centre - Sponsored Content by Microsoft
 
Vulnerabilities & Exploits Whitepapers