Orphan Events
Bulletin Board
Notification Manager
Reporting
Sarbanes Oxley
WhatsUp Pro Integration
Visual Trace Route
Web-Based Administration
Console Mode
Auto Acknowledge
Security Monitoring
Third Party Integration
FAQ
Online Manual
Logalot
Download Logalot
Want to try Logalot? Contact us for an evaluation copy today!

Download Logalot Buy Now!

|Reporting|

One of the highlights in any syslog server should be the reports. Somix takes great pride in the engineering that we have invested into Logalot's reporting engine. Use Logalot to generate reports on specific types of messages or even specific information found in the message body.


(Click to enlarge)

Automated scheduled and emailed reports

Logalot can be setup to email you the status of your log collection every day, week, month, etc.

View an example text report
Open Screenshot

View an example emailed report
Open Screenshot


(Click to enlarge)

Creating a report in Logalot

First you create an initial search to figure out what you actually want to find. Logalot can perform searches on messages collected via eventlog, SMTP, SNMP traps and Syslog.

View an example "Sub Seven Attack Dropped" search
Open Screenshot

If the results of this search displays the data you wanted, you can save the search.
Open Screenshot

Retreive updated data at a later time with the same search criteria.


(Click to enlarge)

Several searches like the one above can be created and saved. Then, multiple searches are run at the same time to create a report with a single graph which includes a data line for every search included in the report. This strategy allows you to identify trends in attacks. In other words, it answers the question: Are the various attacks all occurring at the same time? Some vendors call this "event correlation".

Open Screenshot

If the attacks are happening at the same time, you then need to determine where the attack is coming from (i.e. what IP address(es) is executing the "Port Scan" against the firewall).

With a quick search, you can determine what IP addresses have been performing Port Scans on the firewall. Next, perform a search on each of the IP address and find out what other policies have been violated by these IP address.

You can even graph the above search to determine when the attacks are coming from the IP address to help determine if the attacks are a one time thing or a routine (e.g. every Saturday night at 2:00 A.M.).

Visual Trace Route can then be used to find geographical origin of the attacker.

You can even use the above information to setup a "watch" or policy so that when the perpetrator attacks again, notification can occur in near real time and a posting is made to the bulletin board.

 

Home > Products > Logalot Event Manager > Reporting

spacer
 


Network Traffic Monitoring & Diagnostics Tools
plixer International - Setting Standards in NetFlow & sFlow Analysis
©2006-2008 Plixer International, Inc.

Force103ComEnterasysCisco