ET-SIEM-collateral 0217 C

Download as pdf or txt
Download as pdf or txt
You are on page 1of 2

EventTracker SIEM

Advanced and Comprehensive Security

Overview Pricing
EventTracker SIEM is a comprehensive security platform EventTracker SIEM is available by annual or perpetual
that delivers advanced security tools with audit-ready license, with pricing to fit any budget.
compliance capabilities. It identifies security threats,
malware, unusual behavior and suspicious network traffic Monitor:
and notifies you when you’re under attack.
Today’s network defenses are routinely penetrated as n Antivirus n IDS/IPS
the threatscape is constantly evolving to evade detection. n Applications n Mobile devices
Firewalls, anti- virus and IDS/IPS are essential, but are not
n Behavior n Network devices
enough to prevent cyber-attacks. Further, keeping up with
security at scale, 24x7, across all assets, is more than a n CPU/Disk/Memory n Pre-defined policy
full-time job. Whether your organization has 25 servers Threshold templates
or 2,500, EventTracker SIEM can help by improving log n Custom n Routers
analysis, awareness, detection and incident response applications
across all your servers, workstations, network devices, n Servers/Workstations
locations and teams. n Databases n USB and CD/DVD
EventTracker SIEM ingests millions of security and log n File/folder access n Virtual infrastructure
events and processes them through advanced analytics
to detect and notify when changes in patterns across
users and systems occur, based on unusual behavior
Supported Log File Formats:
and out-of-ordinary access. EventTracker SIEM monitors n Windows n XML
EVT/EVTX
for anomalies and suspicious network activities and
n SYSLOG (TCP/UDP) n IIS/IISW3C/
provides built-in response rules to block or terminate
harmful activities. Integrated threat intelligence provides IIS MSID
n SNMP V1/V2/V3
curated data on bad actors, locations and IP addresses, n TEXT FILE
n CHECKPOINT
both locally and across the globe, to answer who, when
OPSEC LEA n J SON
and where. All your data is organized and presented in
the form of dashboards and reports within EventTracker, n VMWARE API n NETFLOW

and archived to a compressed electronic vault to meet n VULNERABILITY


V5, V9
regulatory retention requirements.
SCANNERS

EventTracker | 8815 Centre Park Drive, Columbia MD 21045


www.eventtracker.com
Features

Automatic Remediation Reporting


The EventTracker family offers automatic remediation EventTracker SIEM provides powerful and comprehensive
capabilities that users can configure using scripting, analytics and reporting engines to allow users to easily
Powershell, Visual Basic, and others. Based on correlated and quickly search, analyze and report on all event data
events that meet serious or critical thresholds, or that either in real-time, for compliance purposes or as part of a
occur after hours, EventTracker SIEM can be set to post-incident forensics process. EventTracker SIEM stores
take immediate, predefined action. events in their original state and the complete contents
are accessible to the user.
Behavior Analysis and Correlation
Real-Time Alerting
Behavior Analysis enables you to quickly detect and
address changes in system and user behaviors. EventTracker SIEM’s alerting capability enables the user to
Automatic baseline learning or flexible rules definitions generate alerts when critical events occur such as security
determine your thresholds for alerting on anomalies breaches or performance problems. The EventTracker
in your infrastructure. Real-time processing and SIEM Alert Console provides a web-based centralized
correlation give you the complete picture of what’s user interface to define and view all alerts. Alerts can
new and different. be prioritized and ordered via a user- configurable
risk-scoring algorithm so important alerts are always
End-Point Security given the attention they require.
EventTracker SIEM provides enhanced end-point
Search and Forensic Analysis
monitoring and security, generating an event when
USB/DVD/CD removable media is inserted including EventTracker SIEM offers the most comprehensive and
the username and device serial number; all file transfers flexible search options in the SIEM/Log Management
to USB devices are recorded; USB devices can be industry. Period! We have spent more than 10 years
automatically disabled based on serial number. working with hundreds of security and sys admin users to
address numerous log search scenarios and use cases.
Incident Handler’s Logbook
Options Available
Electronic Logbook, based on SANS Incident Handlers
Guidebook, records incidents, reports, and changes There are options for modules including Change Audit –
with valuable context, and gives users the ability to File Integrity Monitoring, Configureation Assessment/
flag interesting incidents, reports, configuration SCAP, FIPS 140-2 compliant data transmission, and the
assessment or change audits that enable IT teams availability to have multiple collection points and
to escalate efficiently. collection masters.

About EventTracker EventTracker delivers business critical solutions that transform high-volume cryptic log data into
actionable, prioritized intelligence that will fundamentally change your perception of the utility, value and organizational
potential inherent in log files. Our leading solutions offer Security Information and Event Management (SIEM), real-time
Log Management, and powerful Change and Configuration Management to optimize IT operations, detect and deter
costly security breaches, and comply with multiple regulatory mandates.

EventTracker | 8815 Centre Park Drive, Columbia MD 21045


www.eventtracker.com

You might also like