Feature Description |
ManageEngine EventLog Analyzer
Try now |
FortiSIEM |
Log collection |
Agentless |
|
|
Agent-based |
|
|
Cross platform log collection |
|
|
Heterogeneous server/ device support |
|
|
Import logs |
|
|
Periodical import of logs |
|
|
Log filter |
|
|
Custom log parsing |
|
|
Log collection and processing rate |
20,000 logs/second with peak event handling capacity up to 25,000 logs/second. For Windows event logs the EPS is 2000 logs/second. |
Up to 30,000 logs/second with distributed node deployment. |
Log formats supported |
Windows event log |
|
|
Syslog |
|
|
Any format – with Universal Log Parsing and Indexing (ULPI) technology |
|
|
Amazon Web Services (AWS) EC2 Instance |
|
|
Application logs supported |
Proprietary applications [Microsoft IIS Web Server, FTP Server (W3C logs), Apache Web Server, DHCP Windows, DHCP Linux] |
|
|
Database applications [Oracle Audit, Microsoft SQL Server] |
|
|
Any application – with custom log parsing and indexing technology |
|
|
Other devices supported |
Custom devices [IBM AS400 (iSeries), VMware] |
|
|
Custom devices
- Firewalls
- Intrusion Detection System/ Intrusion Prevention System (IDS/IPS)
- Anti-virus application
- Mail and web application
- Vulnerability Scanners
- Unified threat management solutions
- Symantec DLP Application
- FireEye
- Symantec Endpoint Solution
|
|
|
Alerts and notifications |
Real-time alerts |
|
|
Notification – email, SMS, Run program |
|
|
Compliance alerts |
|
Not specified |
Threat intelligence |
Real-time alerts for global blacklisted IPs intruding the network |
|
|
Reports |
File integrity monitoring |
|
|
Canned reports |
|
|
Custom reports |
|
|
Scheduled reports |
|
|
Report distribution via email |
|
|
Reports in PDF, CSV |
|
|
Drill down to raw logs |
|
|
Management specific reports |
|
|
Trend reports |
|
|
Privileged user activity monitoring reports |
|
|
Log search |
Advanced Search – search any data |
|
|
Advanced search using Boolean, wildcards, grouped search, range search, phrase search |
|
|
Formatted log search |
|
|
Raw log search |
|
|
Save search result as report and as alerts |
|
|
Compliance reports |
Canned reports |
|
|
Customizing report |
|
|
Reports for new compliance |
|
|
PCI-DSS |
|
|
HIPAA |
|
|
FISMA |
|
|
SOX |
|
|
GLBA |
|
|
ISO 27001:2013 |
|
|
Real-time event correlation |
Event correlation |
|
|
User session monitoring |
|
|
File Integrity Monitoring |
Reports on file integrity monitoring |
|
|
Report scheduling |
|
|
Real-time alerts when critical changes are made to files/folders that are being monitored |
|
|
Audit trail of file/folder changes |
|
|
Log archiving |
Flexible periodicity |
|
|
Flexible retention |
|
|
Secured (Encrypted) |
|
|
Tamper-proof |
|
|
Service provider features |
User based views |
|
|
User based dashboards |
|
|
Rebranding |
|
|
User management |
Realm and user-based access |
|
|
Active Directory (AD)-based user authentication |
|
|
RADIUS server-based user authentication |
|
|
Implementation |
Easy to install |
|
|
Web-based client |
|
|
Appliance-based |
|
|
System requirements |
Bundled database (PostgreSQL/MySQL) |
|
|
Windows & Linux platforms support |
|
|
64-bit support |
|
|
Pricing |
Based on number of servers, devices & applications |
|
Based on number of devices and maximum EPS.
|
Annual subscription model |
|
Not specified |
Perpetual licensing model |
|
|