Activity monitoring and security applications
Manage event log data for reliability, security, availability and compliance. Detect and respond to suspicious activity quickly. Monitor availability, performance, and utilization of IT resources.
Distributed by CoreTech · Activity monitoring and security applications
Manage event log data for reliability, security, availability and compliance.
SIEM, infrastructure monitoring, compliance, and advanced event log management.
Good protection strategies should include real-time monitoring of event logs to identify critical security incidents and periodically analyze security-related logs.
This way you can detect and respond to suspicious activity quickly. Monitor policies, mechanisms (authentication, authorization), authorized user activity, and security applications (IDS, IPS, firewall) in real time.
Unplanned system downtime ranges from a minor inconvenience to a major disaster. Monitor the availability, functionality, performance, and utilization of your IT resources: from network devices, workstations, and servers to applications, infrastructure services, and network protocols.
Most data security standards and regulations require that all relevant log data be managed, collected, consolidated and stored securely, so that companies can prove who is responsible for actions that take place in their workplace.
GFI EventsManager offers three-tier log data consolidation, accessible through two-factor authentication, forensic investigation capabilities and compliance reporting.
GFI EventsManager decodes and presents log data in an easy-to-read format, managing at the network level:
GFI EventsManager includes reports tailored to many major compliance regulations, plus reports on account usage and management, policy changes, object access, application management, and print server usage. Reports are flexible and customizable.
Supports retention and review requirements related to Basel II, PCI, Sarbanes-Oxley, Gramm-Leach-Bliley, HIPAA, FISMA, USA Patriot Act, Turnbull Guidance, UK regulations, and the EU data protection directive.
The built-in tools panel includes filter-driven charts: a single point of contact with the data you need to work effectively.
Includes activated criticality rules, the top 10 users with failed or after-hours logins, network service status, volume of archived records, and charts of network connections at application and user level. The panel is highly customizable.
In-depth, granular, rule-based control with immediate support for security information classification for operating systems, applications, and network devices.
Administrators can use predefined rules or create custom ones, and configure alert profiles that notify or run actions (scripts or executables). Scan profiles let you apply rule sets to computers or groups of computers.
Three layers of consolidation: AES encryption of the archive, hashing of entries to prevent tampering, and controlled access via the console.
Access uses two-factor authentication (administrative Windows credentials + built-in user roles). Users work only on data for the resources they manage; all actions are logged and auditable.
Responds to security or IT issues by running code or scripts on remote computers: stop services, uninstall applications, reboot, disable accounts, close connections, activate third-party tools.
Integrates with GFI LanGuard to trigger vulnerability scans or patching when a threat is detected.
In distributed environments it collects data from multiple sites into a central database, monitoring thousands of workstations and servers without excessive impact on bandwidth and memory.