Support
 
Support Get Quote
 
 
 
 

FES enhances security posture, opts for EventLog Analyzer over Splunk

About FES

FES, a non-profit foundation, dedicates itself to assisting communities and non-profit organizations, enabling them to concentrate on their core missions. With a nearly three-decade history, FES has been addressing the requirements of entities serving their communities, including hospitals, schools, and other non-profits. Filament (Filament Essential Services) operates as an affiliate of FES, with a rich history of assisting other non-profits.

FES established the Filament team and a range of services under their purview, with the aim of addressing the time-consuming challenges and talent shortages commonly encountered by non-profit organizations. The foundation supports organizations by establishing a professional presence, promoting their causes, enhancing IT security, and setting up networks or websites.

Company

FES

Industry

Non-profit

Location

USA

Main challenges faced by FES before EventLog Analyzer

FES recognized the imperative need for a robust log management solution to meet the stringent insurance requirements (NIST SP 800-53 Rev 5). The primary objective was not only compliance but also the enhancement of overall cybersecurity measures.

  • Insights into logging One of the main challenges faced by the organization revolved around gaining actionable insights from scattered logs hosted across various platforms. This decentralized approach not only hindered efficient threat detection but also posed challenges during compliance audits.
  • Splunk consideration While considering Splunk as an alternative, the organization encountered a bottleneck in terms of time constraints for deploying Splunk's heavy forwarder. This led to a reevaluation of options, ultimately steering towards EventLog Analyzer.

FES security needs met

Brett Lechner, a senior network engineer at FES, mentioned that the organization faced threats like denial of service attacks, phishing, and brute force attempts due to the public exposure of services. With the help of EventLog Analyzer's real-time alerts, they were able to identify and respond to security threats promptly.

He also mentioned that the built-in reports helped him gather information, thereby significantly reducing manual efforts, expediting the audit process, and ensuring compliance with industry standards.

"There's just a lot of pre-built alerts, rules, and reporting [in EventLog Analyzer] that saves a lot of time that we could have done manually. Before, we would have had to go through and research the event ID with the Windows event ID, and which alert that correlates to. And then just manually create all of that."

Brett Lechner, Sr. Network Engineer, FES

Impact

According to Lechner, the main reason behind choosing EventLog Analyzer was due to its user-friendly deployment compared to Splunk. The solution allowed the consolidation of logs, providing more meaningful information.

Post-implementation, the organization experienced a remarkable reduction in the time taken to detect security threats. Within a week, Event Log Analyzer showcased its effectiveness in providing timely threat intelligence.

He also mentioned that he would highly recommend ManageEngine's onboarding services, and appreciated the team's willingness to share how the product works behind the scenes and get into its technical details. This helped FES have a better idea of how to tailor the alerts feature.

About custom onboarding

Custom onboarding is a ManageEngine service that provides solution implementation to clients upon request. This service includes installation and customized configuration of ManageEngine solutions. It enables clients to seamlessly begin work without worrying about the complexities of installation, deployment, and product use. Every client environment is unique and requires additional support beyond the basic installation and standard features. With custom onboarding, clients have the option to engage a team of product experts to manage the installation, implementation, customization, and training based on the business needs.

About EventLog Analyzer

EventLog Analyzer is complete log management software that provides holistic cybersecurity. It collects, analyzes, and manages log data from over 700 log sources. With real-time security auditing capabilities, it's easier to monitor critical changes in all your end-user devices. EventLog Analyzer offers instant threat detection to uncover security threats using event correlation and threat feed analysis, and instant mitigation using automated workflows. For more information about EventLog Analyzer, visit manageengine.com/products/eventlog/.

Similar case studies

 

Take control of your identity security posture with ADSelfService Plus

Discover how ADSelfService Plus helps your organization manage and protect identities through a personalized self-service experience

Get your copy now!

Fill in the details below and get instant access to the case study.

  •  
  •  
  • By clicking " Submit now", you agree to processing of personal data according to the Privacy Policy.
A Single Pane of Glass for Comprehensive Log Management