Feature Description |
ManageEngine EventLog Analyzer
Try now |
McAfee SIEM |
Log collection |
Agent-less |
|
|
Agent-based |
|
Not specified |
Cross platform log collection |
|
|
Heterogeneous server/ device support |
|
|
Import logs |
|
|
Periodical import of logs |
|
|
Log filter |
|
|
Custom log parsing and indexing |
|
|
Log collection and processing rate |
20,000 logs/second with peak event handling capacity up to 25,000 logs/second. For Windows event logs the EPS is 2000 logs/second. |
Not specified |
Log formats supported |
Windows event log |
|
|
Syslog |
|
|
Any format – with custom log Parsing and indexing technology |
|
|
Amazon Web Services (AWS) EC2 Instance |
|
|
Application logs supported |
Proprietary applications [Microsoft IIS Web Server, FTP Server (W3C logs), Apache Web Server, DHCP Windows, DHCP Linux] |
|
Microsoft IIS and Apache Web Server are supported. Other, not specified. |
Database applications [Oracle Audit, Microsoft SQL Server] |
|
|
Any application – with custom log parsing and indexing |
|
|
Other devices supported |
Custom devices [IBM AS400 (iSeries), VMware] |
|
Not specified |
Custom devices
- Firewalls
- Intrusion Detection System/ Intrusion Prevention System (IDS/IPS)
- Anti-virus application
- Mail and web application
- Vulnerability Scanners
- Unified threat management solutions
- Symantec DLP Application
- FireEye
- Symantec Endpoint Solution
|
|
Not specified |
Alerts and notifications |
Real-time alerts |
|
|
Notification – email and SMS |
|
Email and Run program |
Compliance alerts |
|
|
In-built incident management module |
|
|
Forward tickets to external help desk software |
ServiceDesk Plus and ServiceNow |
|
Threat intelligence |
Real-time alerts for global blacklisted IPs intruding the network |
|
|
Reports |
File integrity monitoring |
|
|
Canned reports |
|
|
Custom reports |
|
|
Scheduled reports |
|
|
Report distribution via email |
|
|
Reports in PDF, CSV and HTML formats |
|
Plug-in required for this function |
Drill down to raw logs |
|
|
Filter using mouse gesture |
|
Not specified |
Management specific reports (Ask ME) |
|
Not specified |
Trend reports |
|
|
Privileged user activity monitoring reports |
|
Not specified |
Log search |
Advanced search using Boolean, wildcards, grouped search, range search, phrase search |
|
|
Formatted log search |
|
|
Raw log search |
|
|
Save search result as report and as alerts |
|
|
Compliance reports |
Canned reports |
|
|
Customizable report |
|
|
Reports for new compliance |
|
Not specified |
PCI-DSS |
|
|
HIPAA |
|
|
FISMA |
|
|
SOX |
|
|
GLBA |
|
|
ISO 27001 |
|
|
Real-time event correlation |
Event correlation |
|
|
User Session monitoring |
|
Not specified |
File Integrity Monitoring |
Reports on file integrity monitoring |
|
|
Report scheduling |
|
|
Real-time alerts when critical changes are made to files/folders that are being monitored |
|
|
Audit trail of file/folder changes |
|
|
Log archiving |
Flexible periodicity |
|
|
Flexible retention |
|
|
Secured (Encrypted) |
|
|
Tamper-proof |
|
|
Service provider features |
User based views |
|
|
User based dashboards |
|
|
Rebranding |
|
|
User management |
Realm and user-based access |
|
Not specified |
Active Directory (AD)-based user authentication |
|
Not specified |
RADIUS server-based user authentication |
|
Plug-in required for this function |
Implementation |
Easy to install |
|
|
Web-based client |
|
|
Appliance-based |
|
|
System requirements |
Bundled database (PostgreSQL/MySQL) |
|
|
Windows & Linux platforms support |
|
RHEL 6.x/7.x or CentOS 6.x/7.x Windows is not supported |
64-bit support |
|
|
Pricing |
Based on number of servers, devices & applications |
|
Nagios Log Server is licensed based on the number of cluster Instances implemented the environment. |
Annual licensing model |
|
|
Perpetual licensing model |
|
|