Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Security event management software

NetIQ's Security Manager does an impressive job sorting through security.
By Mandy Andress, Network World Lab Alliance , Network World , 07/19/2004
  • Share/Email
  • Comment
  • Print

The power and complexity of NetIQ's Security Manager 5.0 - the latest version of the company's security event management product - is well masked by its consistent user interface and overall ease of use.

When we first tested security event management products late last year, NetIQ opted out because it was working on this new version of its product. Measured using the same methodology as our original test, Security Manager 5.0 places a close second to ArcSight's ArcSight 2.5 product, which earned top honors (see "ArcSight's flexibility and interface helps it lead the pack of security data organizers"). Security Manager is easy to install and is scalable, but the ArcSight product supports more devices out-of-the-box and has a slightly better GUI.


How we did it
Archive of Network World reviews
Subscribe to the Product Review newsletter


Security Manager comprises three main components: Event Manager, Intrusion Manager and Log Manager. Event Manager is the central console that manages and displays security events. Intrusion Manager watches incoming logs for signs of intrusion and either generates alerts or takes a defined action when an incident is suspected. Log Manager is the workhorse, handling collection, standardization and archiving of all managed logs. In our tests, we installed all components on one server without running into performance issues (see How we did it). For a production environment where you would watch a large number of events, you'd probably want to split these components up onto multiple machines.

Security Manager is an agent-based product, with agents available for servers running various flavors of Windows and Unix/Linux. These agents cull the servers' event logs. They perform initial rule analysis on the incoming events and forward them to a central database. Security Manager also includes a proxy agent - which must reside on a Windows machine - that effectively acts as a syslog server and taps into other security and network devices such as firewallsintrusion-detection systems and routers.

Security Manager uses wizards to perform most tasks, such as agent installation and correlation definition. This is one of Security Manager's greatest strengths, as each wizard maintains a consistent interface to minimize training. We used the agent installation wizard to install agents on our Windows and Unix systems, and to install proxy agents to capture Check Point, Snort and Cisco switch logs. Setup for Snort logging was simple and took just minutes following the instructions provided in the Security Manager documentation.

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comments (2)
Login
Forgot your account info?

Event Management HysteriaBy meatpieandtatters on November 8, 2007, 9:01 amI still can't figure out why anybody would need this kind of headache. An event management platform? And expensive too boot? And what does it do: generate alarms...

Reply | Read entire comment

RE: Security event management softwareBy MICHAEL McMULLEN on September 26, 2007, 10:27 amDear Sir / Madam, I own and run a successful manpower security company here in Dubai, U.A.E. We handle the security arrangements for all the rock concerts, grand...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed