McAfee Enterprise Log Manager automates log management and analysis for all log types, including Windows Event logs, Database logs, Application logs, and Syslogs. Logs are signed and validated, ensuring authenticity and integrity — a necessity for regulatory compliance. Out-of-the-box compliance rule sets and reports make it simple to prove your organization is in compliance and policies are being enforced.
Using this tightly integrated log collection, management, and analysis environment will both strengthen your security profile and dramatically improve your ability to comply with over 240 standards, such as PCI DSS, HIPAA/HITECH, NERC-CIP, FISMA, GLBA, and SOX.
Intelligent log management — Enterprise Log Manager collects logs intelligently, storing the right logs for compliance, and parsing and analyzing those logs for security. You can retain logs in their original format for as long as you require for specific compliance needs. Since we do not alter the original log files, McAfee supports chain of custody and non-repudiation efforts.
Integrated with Enterprise Security Manager — Enterprise Log Manager is an optional, integrated part of McAfee Enterprise Security Manager. While Enterprise Log Manager stores the logs, they can be deeply parsed, normalized, and analyzed by Enterprise Security Manager. Log information is immediately available for real-time security investigations and incident response.
Collect, sign, and store any log type in its original format for as long as you require to support your specific compliance needs.
Use easily customizable storage pools to ensure that your logs are stored correctly and for the right amount of time.
Differentiate logs stored for compliance from logs to be parsed and analyzed for security.
Choose the best storage option for your needs — with up to 7.5 TB of usable HDD storage on the appliances, and optional fiber channel cards for high-speed SAN storage.
Get one-click access to original log files and even the specific log record from any point in the event management process.
Provide log management and retention capabilities to support advanced use cases, including:
|Collection Rates||75,000 events per second||50,000 events per second||40,000 events per second|
|Analytical Performance||14 TB||8 TB||3 TB|
Built for big security data, McAfee Global Threat Intelligence for McAfee Enterprise Security Manager (ESM) puts the power of McAfee Labs directly into the security monitoring flow using McAfee’s high-speed, highly intelligent security information and event management (SIEM) solution.
The security information and event management (SIEM) market is defined by the customer's need to analyze security event data in real time for internal and external threat management, and to collect, store, analyze and report on log data for regulatory compliance and forensics. The vendors that are included in Gartner’s analysis have technologies that have been designed for this purpose, and they actively market and sell these technologies to the security buying center.
McAfee integrates NitroSecurity products into its portfolio, improving its SIEM offering.
Topics : SIEM
McAfee spoke with customers about integrating SIEM with Threat Intelligence and how it helped their effort to mitigate bad actors.
Learn about the top five issues with SIEM: Big Security Data, Content and User Awareness, Dynamic Context, Solution Customization, and Business Value.