|
|
 |
| QRadar Log Manager |
| QRadar Log Manager QRadar Log Manager is a comprehensive solution for organizations that are looking to implement a distributed log management offering to collect, archive, and analyze network and security event logs. |
Log management has emerged as a required part of an organization's ability to deliver security best practices and meet specific auditing and reporting requirements of various government regulations, including:
- Payment Card Industry Data Security Standard (PCI DSS)
- North American Electric Reliability Corporation (NERC)
- Health Insurance Portability and Accountability Act (HIPAA)
- Sarbanes-Oxley (SOX), and Federal Information Security Management Act (FISMA)
QRadar Log Manager provides numerous advantages over other log management solutions, including:
Easy Deployment:
- Simple and easy-to-use solution for secure and efficient log management
Distributed log collection and archival
- Scales to support any size enterprise network
Policy-driven event correlation:
- Hundreds of useful, out-of-the box correlation rules provide immediate value to users
Effective reporting and compliance auditing:
- Compliance-driven report templates meet specific regulatory reporting and auditing requirements
Reliable and tamper-proof log storage:
- Supports extensive log file integrity checks, including NIST Log Management Standard SHA-x (1-256) hashing for tamper-proof log archives
Simple upgrade to full QRadar SIEM:
- A fully scalable appliance family, QRadar Log Manager can also be easily upgraded via a software license key to Q1 Labs' highly acclaimed QRadar SIEM solution - providing users with a seamless migration path to full SIEM capabilities - as an organization's requirements change and a more comprehensive threat and compliance management system is needed
QRadar Log Manager Appliance:
The QRadar Log Manager appliance is an enterprise-class log management appliance that combines ease of deployment with a robust and scalable log management solution. QRadar Log Manager leverages QRadar's core correlation capabilities to provide best in class compliance and policy driven analysis and alerting as well as unparalleled ease of use for monitoring log activity in real time and historically. In addition, QRadar's Log Manager can be upgraded to full SIEM capabilities for enhanced work flow through a simple license key, leveraging your existing appliance investements.
QRadar Log Manager Processor Appliances:
The QRadar Log Manager architecture supports an easy to deploy scalable model through the use of Processor Appliances, such as the QRadar 1601 and QRadar 1605 that provide 2 or 6 Terabytes of dedicated secure storage for logs and performs real time correlation of logs up to 20,000 messages per second.
|
|
|