Threat Intelligence Data Analytics
EventLog Analyzer supports the log data of threat intelligent solutions such as Symantec Endpoint solution, Symantec DLP application, and FireEye. The solution provides out-of-the-box reports and alert conditions that help in detecting and mitigating external security threats at the earliest. The predefined reports can be exported to various formats like PDF, CSV, and HTML. Report generation can also be automated using 'Schedule report' option
How to add a threat intelligent solution for monitoring
With EventLog Analyzer, adding log data of a threat intelligent solution mentioned above is quite easy.
- Associate the host in which the threat intelligent solution has been installed. Logs will be collected/imported from this host
- Select the type of application viz., FireEye, Symantec Endpoint solution, or Symantec DLP application
Note: The host you're associating should have been already added. If not, add the respective host first and then associate it to the threat intelligent solution.
FireEye Log Data Analytics
EventLog Analyzer provides out-of-the-box reports that help in analyzing FireEye application logs.
The solution provides predefined reports for the events such as
- Domain matches
- Malware infection
- Malware object
- Web infection
It also provides reports that give information on top
- Source IPs from which infection originates
- Target IPs
- Target ports
- Active sensors
Symantec Endpoint Solution Log Analytics
EventLog Analyzer can analyze Symantec Endpoint solution logs and generate reports on important events that help you in identifying and containing the virus/malware infection at the earliest and thereby mitigate external security threats.
The solution generates out-of-the-box reports for
- Security risks
- Virus detected
- Port cans
- Installation of commercial applications
- Threat activities
- HIPS activities
EventLog Analyzer also provides top level reports for
- Affected hosts
- Source hosts
Symantec DLP Application Reports
EventLog Analyzer supports Symantec Data Loss Prevention Application logs. It generates predefined reports and alerts for the following events.