|
Highly
Refined Compliance Reports on Key
Security Events of Your Network
Often there is some confusion among
users as to which event reports are
needed for meeting the requirements of
different compliance acts. GFI
EventsManager solves this problem by
providing you with specific reports for
some of the major compliance acts as
well as many
other standard reports.
GFI
EndPointSecurity Data Integration
GFI EventsManager offers dedicated
processing rules, available
out-of-the-box, that allow users to
automatically categorize, report and
alert on the events generated by GFI
EndPointSecurity. These events are also
present in different reports which are
useful both for network monitoring and
regulatory compliance purposes.
For those who also
have GFI LANguard, GFI EventsManager can
also process that product’s results to
offer an enhanced compliance reporting
experience by providing the necessary
compliance information in a single
location.
Centralized
Event Logging Event logs are
constantly and automatically generated
by a user or by an automatic or
background process. Logs are often
stored in disparate locations. GFI
EventsManager stores all captured event
logs into one SQL database that may even
reside remotely. Through GFI
EventsManager you can configure
scheduled backups of your event logs.
Analysis of
Event Logs including SNMP Traps, Windows
Event logs, W3C logs,
SQL Server.
As a network administrator, you have
experienced the cryptic and voluminous
logs that make log analysis a daunting
process. GFI EventsManager is a log
processing solution that provides
network-wide control and management of
Windows event logs, W3C logs, SQL Server
audit logs and Syslog events generated
by your network sources. GFI
EventsManager supports Simple Network
Management Protocol, the language spoken
by low level devices such as routers,
sensors, firewalls, etc. Through SNMP
users can monitor a whole range of
hardware devices on their infrastructure
and gain the ability to report on the
health and operational status of each
device.
Auto-archive
All Events into Files Due to
the relatively large number of events
that must be kept for investigation and
compliance purposes, it takes no time
for the events database to reach its
maximum capacity. To alleviate this
issue, GFI EventsManager allows
administrators to auto-archive all
events into files in parallel with
processing the events through rules with
important events only being saved into
the database. Moreover, GFI
EventsManager features the rollover
backup databases which automatically
trigger and manage the backup process.
Powerful
Dashboard The GFI
EventsManager dashboard includes a
number of filtering-enabled charts to
provide administrators with fast and
easy access to the data they need as
they go about their day. These include
the top critical and high importance
rules triggered within a certain period
of time, the top 10 users who fail to
log on or who log on during and outside
working hours, service status across
network, how many events are stored in
the database per log type and a
comprehensive graph based on Windows
events that shows network connections at
application and user level . The
dashboard is highly customizable and can
be zoomed individually in separate
windows that can be automatically
arranged on the desktop to show real
time data about the most important
events.
One-click
Rule and Filter Creation You
can create processing rules and filters
for Windows events by simply
right-clicking on event details in the
Events Browser Tool. New rules are
automatically saved into a new rule set
called User Rules and will have the
least priority by default.
Real-time
Alerts, SNMPv2 Traps Alerting Included
GFI EventsManager™ has improved alert
level for key events or intrusions that
are detected on the network. GFI
EventsManager allows you to trigger
actions such as scripts or to send an
alert to one or more people by email,
network messages, SMS notifications sent
through an email-to-SMS gateway or
service and includes SNMPv2 traps. The
generation of SNMP alerts will also
allow administrators to integrate GFI
EventsManager with pre-existing or
generic monitoring mechanisms.
Password
Recovery GFI EventsManager
enables a password reminder email to be
sent to the administrator’s registration
email address should they lose or forget
it.
Detection of
Windows Events that Refer to
Administrators GFI
EventsManager can detect if a Windows
event refers a user who is an
administrator user, a feature that is
required by certain regulations. GFI
EventsManager checks the details of
events and probes whether the user names
or SIDs in question correspond to
administrator users. The product can
also track changes in rights assignment
so that if a user becomes or stops being
an administrator by the time an event
has been generated, GFI EventsManager
will report accordingly.
New! Auto
Update GFI EventsManager
users can now benefit from the latest
product patches and updates in a very
easy and straightforward manner, thanks
to the solution’s auto-update
feature. This periodically checks if
there are new patches for the current
version of the product, downloads the
patches from the GFI website and
installs them automatically.
GFI
EventsManager Audit for Windows
GFI EventsManager offers an audit system
for Windows machines. It works through a
scanning system based on checks which
are pre-programmed. When a regular log
scan is started on a Windows computer,
EventsManager Audit, when enabled, will
execute all the selected checks. Once
checks are done, their results will be
written as events in the Windows
application log of that machine or the
local machine. After the audit, the
usual log scanning will start and the
new audit events will be available for
processing too. Event processing rules
can be defined to process the result of
the checks.
Deeper
Granular Control of Events
GFI EventsManager helps you monitor a
wider range of systems and devices
through the centralized logging and
analysis of various log types including
Windows events, Syslog, W3C and SNMP
traps that are generated by network
resources. Administrators can gather
information from Windows machines and
third-party devices at a greater level
of granularity and process information
at extended tags level, basing the
decision of what to do with that
information on the spot, without further
information management.
New! Record
What Really Happens Behind the Scenes in
SharePoint GFI EventsManager
grants visibility of user activity on
SharePoint, through a tool called
LogBinder SP (developed by Randy
Franklin Smith, a renowned security
expert, and GFI EventsManager).
LogBinder SP sits on top of a SharePoint
server and tracks users’ activities. The
data is presented in a readable format
as Windows events which GFI
EventsManager can process and manage
through dedicated reports.
Computer
Discovery and Domain Synchronization
It is possible to configure GFI
EventsManager by automatically detecting
computers from the network or by
automatically synchronizing computer
groups with computers from domains.
Support for
New Devices Managing SNMP
Trap for myriad devices requires the
ability to understand the language each
manufacturer uses to define events.
These definitions and the device
information are contained in Management
Information Base (MIB) definition files,
provided by the manufacturers. GFI
EventsManager ships with MIB definitions
for the following vendors: Cisco, 3Com,
IBM, HP, Check Point, Alcatel, Dell,
Netgear, SonicWall, Juniper Networks,
Arbor Networks, Oracle, Symantec, Allied
Telesis and others. GFI EventsManager is
capable of importing the MIB files.
SQL Server
Auditing GFI EventsManager
supports SQL server auditing for all
commercial and free versions of SQL
Server including 2000, 2005, 2008, MSDE
and SQL Express. Auditing allows the
user to track and report on SQL server
activity such as: Running of SQL
statements, altering DB tables, attempts
to access data without necessary
privileges, etc. This can ensure data in
SQL servers is authentic and thus
reliable.
New! Oracle
Audit Support Many companies
use Oracle database servers and the
activity on these servers need to be
monitored for security or regulatory
compliance purposes. GFI EventsManager
can process Oracle audit records for
versions 9i, 10g, and 11g.
Translates
Cryptic Windows Events
Cryptic logs make log analysis a painful
and lengthy process. GFI EventsManager
translates those event descriptions to
clear, concise explanations and
suggestions for action.
High
Performance Scanning Engine
GFI EventsManager incorporates a totally
redesigned event scanning engine that is
fine-tuned for maximum scanning
performance. Tests demonstrate that our
engine is able to scan and collect up to
six million events per hour. Its plug-in
based methodology allows additional
features and modules to be integrated
without interfering with existing code.
Collect
Events Data Distributed Over a WAN into
One Central Database You can
collect events data from GFI
EventsManager installations on multiple
sites and locations across your network
into one central database using the
Database Operations functionality. This
enables you to easily monitor thousands
of workstations and servers across the
network without impacting bandwidth and
storage use. It integrates and
centralizes events collected and
processed and allows you to backup and
restore events on demand.
New! Export
Events into Customizable HTML files
GFI EventsManager can export events from
the event browsers into HTML format,
based on templates which can be
customized. These templates make it
possible to choose the columns for
reporting and perform column mappings.
The layout of the HTML template can also
be customized by editing the
corresponding .css file.
Rule-based
Event Log Management GFI
EventsManager ships with a
pre-configured set of log processing
rules that allow you to filter and
classify events that satisfy particular
conditions. You can either run these
default rules without performing any
configuration, or you can choose to
customize these rules and create
tailored ones that suite your network
infrastructure.
Advanced
Event Filtering Features GFI
EventsManager’s powerful filtering sifts
through recorded event logs allowing you
to browse without deleting any records
from your database backend. You may also
selectively highlight specific events
using a color or the integrated event
finder tool.
Event Log
Scanning Profiles Scanning
profiles allow you to configure the set
of event log monitoring rules that will
be applied to a specific computer or to
a group of computers. Profiles provide a
centralized way of tuning event log
processing rules. You can, for example,
set up a set of rules that only apply to
workstations in a particular department.
Or you might create separate
complementary profiles that provide
additional and more specialized event
log rules on a computer by computer
basis.
Ensures
compliancy with PCI DSS and other
regulations Data logging is
key to meeting the requirements of
different compliance regulations like:
Payment Cards Industry (PCI DSS)
Standard, HIPAA, FISMA, GLBA and others.
All businesses handling cardholder data,
regardless of size, must be fully
compliant with strict security standards
drawn up by the world’s major credit
card companies. Logs provide audit
trails of all activities in a credit
card holder data environment and hence,
a comprehensive log management system.
Support for
Virtual Environments
Organizations that are currently using
or plan to use virtualization on their
network can still install and use a
range of GFI products with confidence.
GFI EventsManager supports and runs on
the most common virtualization
technologies in use, namely VMware,
Microsoft Virtual Server and Microsoft
Hyper-V.
|