GFI EventsManager

Activity monitoring and security applications

Analyze log data for SIEM purposes Monitor and manage your entire IT infrastructure Consolidate log data for compliance purposes

Manage event log data for reliability, security, availability and compliance. Detect and respond to suspicious activity quickly. Monitor availability, performance, and utilization of IT resources.

Distributed by CoreTech · Activity monitoring and security applications

What it is

Manage event log data for reliability, security, availability and compliance.

  • Analyze log data for SIEM purposes
  • Monitor and manage your entire IT infrastructure
  • Consolidate log data for compliance purposes
GFI EventsManager console
Benefits

Technical benefits

  • Real-time SIEM analysis — monitor policies, authentication, authorization, and security applications
  • Broad source support — Windows, W3C, SQL/Oracle, Syslog, SNMP, and text files
  • Granular control — classification rules, scan profiles, and active alerts
  • Secure archiving — AES encryption, hashing, and two-factor authentication

Strategic benefits

  • Regulatory compliance — consolidation and reports for PCI, SOX, HIPAA, GDPR, and other regulations
  • Reduced downtime — monitoring of availability, performance, and resource utilization
  • Responsiveness and remediation — remote scripts, integration with GFI LanGuard for patches and vulnerabilities
  • IT productivity — unified dashboard and centralized management even in distributed environments
Features

SIEM, infrastructure monitoring, compliance, and advanced event log management.

SIEM analysis of log data

Good protection strategies should include real-time monitoring of event logs to identify critical security incidents and periodically analyze security-related logs.

This way you can detect and respond to suspicious activity quickly. Monitor policies, mechanisms (authentication, authorization), authorized user activity, and security applications (IDS, IPS, firewall) in real time.

IT infrastructure monitoring

Unplanned system downtime ranges from a minor inconvenience to a major disaster. Monitor the availability, functionality, performance, and utilization of your IT resources: from network devices, workstations, and servers to applications, infrastructure services, and network protocols.

Compliance and log consolidation

Most data security standards and regulations require that all relevant log data be managed, collected, consolidated and stored securely, so that companies can prove who is responsible for actions that take place in their workplace.

GFI EventsManager offers three-tier log data consolidation, accessible through two-factor authentication, forensic investigation capabilities and compliance reporting.

Wide support for log sources

GFI EventsManager decodes and presents log data in an easy-to-read format, managing at the network level:

  • Windows event logs (Microsoft servers, workstations, and applications)
  • W3C logs (IIS, ISA, MS Exchange, and others)
  • SQL Server and Oracle audit logs
  • Syslog (Unix/Linux and network devices)
  • SNMP traps and generic text files
Compliance reports

GFI EventsManager includes reports tailored to many major compliance regulations, plus reports on account usage and management, policy changes, object access, application management, and print server usage. Reports are flexible and customizable.

Supports retention and review requirements related to Basel II, PCI, Sarbanes-Oxley, Gramm-Leach-Bliley, HIPAA, FISMA, USA Patriot Act, Turnbull Guidance, UK regulations, and the EU data protection directive.

Interface and dashboard

The built-in tools panel includes filter-driven charts: a single point of contact with the data you need to work effectively.

Includes activated criticality rules, the top 10 users with failed or after-hours logins, network service status, volume of archived records, and charts of network connections at application and user level. The panel is highly customizable.

Granular control and rules

In-depth, granular, rule-based control with immediate support for security information classification for operating systems, applications, and network devices.

Administrators can use predefined rules or create custom ones, and configure alert profiles that notify or run actions (scripts or executables). Scan profiles let you apply rule sets to computers or groups of computers.

Secure archiving

Three layers of consolidation: AES encryption of the archive, hashing of entries to prevent tampering, and controlled access via the console.

Access uses two-factor authentication (administrative Windows credentials + built-in user roles). Users work only on data for the resources they manage; all actions are logged and auditable.

Responsiveness, remediation, and distributed environments

Responds to security or IT issues by running code or scripts on remote computers: stop services, uninstall applications, reboot, disable accounts, close connections, activate third-party tools.

Integrates with GFI LanGuard to trigger vulnerability scans or patching when a threat is detected.

In distributed environments it collects data from multiple sites into a central database, monitoring thousands of workstations and servers without excessive impact on bandwidth and memory.