|
Logalot Quick Crunch(TM) message correlation technology is used to scrutinize all network and security messages using one platform. Security administrators gain real-time message management and insight into the biggest threats and problems facing the enterprise.
The Bulletin Board is ultimately where all of the messages you really want to see end up. It is Logalot's responsibility to remove the "informational" messages that tend to clutter a log on a specific device. Once all of the less important messages are removed, we can finally focus on what is important. These are the messages that make it to the Bulletin Board. If the "SYN flood attack dropped " violation in the above Screenshot is clicked, Logalot will list the actual events. In this example, the device or person (216.204.147.209) that performed the SYN flood attack is an internal internet web server that may have been hacked. Further reports can then be carried out to see if this server has made any other hacking attempts. Notifications can also be configured. Visual Trace Route can then be used to find geographical origin of the attacker. If you have WebNM, you can search by IP address and find out more about the computer or which switch and port the computer resides on.
|
||||||||||||||||||||
![]() |
|||||||||||||||||||||
|
|||||||||||||||||||||