LogRhythm v4.0

This is a serious log analysis tool. It covers all the bases you need to cover for network forensics. The appliance contains all the features you would expect in a SIEM solution, plus the ones you need for managing log evidence.

In a forensic environment you would save the raw logs in a chain of custody and perform all analysis on LogRhythm's archived data, never taking the chance of corrupting actual evidence.

The appliance is easy to set up and deploy. Since it is watching the network all the time in its role as a log correlator and analyser, it will have everything you need to perform network forensics.

It can take data from most types of logs found on a network. Plus, its Universal Database Log Adapter lets it gather logs from most types of database systems. This is a major forensic benefit.

One of LogRhythm's best features is the Log Miner. This function provides multiple, innovative ways to view log data from multiple sources. The displays tell a story very quickly, leading to drill-downs that access exactly what you are looking for. Newly improved handling of log metadata adds to the high performance.

LogRhythm provides good documentation to meet the needs of both administrators and end users. The product comes with all user, administrator and appliance manuals to make operations and deployment straightforward.

The administrator's guide contains deployment and management documentation as well as "how to" examples to assist users from start to finish. The documentation is well laid out and easy to follow, with good examples and script code.

Support offerings include web, email and phone assistance. LogRhythm also offers a support portal with specific resources to help customers troubleshoot problems. Other available services provided by LogRhythm are deployment and implementation planning, custom configuration, training and managed services.

Starting at US$20,000, this is a very good value, even if all you want it for is forensics. If you plan to implement the LogRhythm appliance as a full featured SIM, it’s an even better deal.
LogRhythm v4.0
Verdict
5 out of 5
For: One of the best network log analysis tools we've seen
Against: Nothing that we found
Verdict: Top-end network analysis tool. This gave our Best Buy a strong run for its money, but still we rate it Recommended
Info
Supplier:
LogRhythm
Keywords
Related

What are your thoughts on this article? Add your comment below.

To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.

NOTE: You must be a registered member of SC Magazine to post a comment.

Click here to login | Click here to register
comments powered by Disqus
Sign up to receive SC Magazine email newsletters
   FOLLOW US...
Most Read