07.06.2013 Views

syslog-ng Store Box - BalaBit

syslog-ng Store Box - BalaBit

syslog-ng Store Box - BalaBit

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

CENTRAL LOG SERVER FOR HETEROGENEOUS ENVIRONMENTS<br />

■ Central logserver appliance<br />

■ Complete log-lifecycle management<br />

■ Encrypted, signed, and timestamped log storage<br />

■ Web-based configuration interface and log search<br />

■ Log collector agent for Windows, IBM System i and<br />

Unix-variant hosts<br />

<stro<strong>ng</strong>>syslog</stro<strong>ng</strong>>-<strong>ng</strong> <strong>Store</strong> <strong>Box</strong><br />

trusted log collection and storage<br />

■ Fast search capability via log message indexi<strong>ng</strong><br />

■ Forward logs to external database or SIEM devices<br />

■ Up to 10 Terabytes of effective disk space<br />

■ Collect more than 100,000, and index more than<br />

75,000 log messages per second real-time<br />

Are you looki<strong>ng</strong> for a simple way to store your logs in one place? Do you need to prevent unauthorized access to<br />

your logs? Do you need a reliable platform with excellent hardware support and high availability? Is your loggi<strong>ng</strong><br />

infrastructure subject to policy compliance?<br />

Built around the popular <stro<strong>ng</strong>>syslog</stro<strong>ng</strong>>-<strong>ng</strong> application used by thousands of organizations worldwide, the <stro<strong>ng</strong>>syslog</stro<strong>ng</strong>>-<strong>ng</strong> <strong>Store</strong> <strong>Box</strong><br />

(SSB) bri<strong>ng</strong>s you a powerful, easy to configure appliance to collect and store your logs. SSB allows you to collect, process,<br />

and store log messages from a wide ra<strong>ng</strong>e of platforms and devices.<br />

www.balabit.com


Secure, reliable log transfer<br />

The <stro<strong>ng</strong>>syslog</stro<strong>ng</strong>>-<strong>ng</strong> <strong>Store</strong> <strong>Box</strong> collects and classifies log messages from a<br />

wide variety of devices and applications and can receive log messages<br />

sent usi<strong>ng</strong> both the legacy BSD-<stro<strong>ng</strong>>syslog</stro<strong>ng</strong>> protocol, as well as the latest<br />

<stro<strong>ng</strong>>syslog</stro<strong>ng</strong>> protocol standards. Transferri<strong>ng</strong> messages to SSB is supported<br />

usi<strong>ng</strong> the UDP, TCP, and TLS protocols. Mutual authentication of the<br />

TLS- encrypted channels maintains the integrity and confidentiality of<br />

transferred information. Usi<strong>ng</strong> <stro<strong>ng</strong>>syslog</stro<strong>ng</strong>>-<strong>ng</strong> to transfer the log messages<br />

helps you avoid losi<strong>ng</strong> messages even in case of network or hardware<br />

errors.<br />

Web-based configuration and access<br />

SSB can be conveniently configured from a browser usi<strong>ng</strong> a simple,<br />

clean user interface. Logs, includi<strong>ng</strong> logs stored remotely on a remote<br />

backup server, are also accessible and can be browsed from the SSB<br />

interface. SSB also features highly customizable access control –<br />

you can specify exactly who has access to certain parts of the SSB<br />

configuration, or to log messages. User groups and privileges can be<br />

retrieved from your LDAP server (e.g., from Microsoft Active Directory).<br />

Configuration cha<strong>ng</strong>es are automatically logged.<br />

Handle extreme load<br />

The <stro<strong>ng</strong>>syslog</stro<strong>ng</strong>>-<strong>ng</strong> <strong>Store</strong> <strong>Box</strong> is optimized for performance, and can handle<br />

enormous amount of messages. Dependi<strong>ng</strong> on its exact configuration,<br />

it can collect over 100,000 messages per second, and index over<br />

75,000 messages per second, and process over 35 GB of raw logs per<br />

hour. Larger versions of the appliance are capable of stori<strong>ng</strong> up to 10<br />

Terabytes of data.<br />

Direct database access<br />

SSB natively supports SQL database sources allowi<strong>ng</strong> users to fetch log<br />

messages directly from MySQL, Microsoft SQL (MSSQL), Oracle, and<br />

PostgreSQL databases. In addition to stori<strong>ng</strong> messages locally on SSB,<br />

log messages can be transferred directly to SQL databases.<br />

Trusted, timestamped log storage<br />

The <stro<strong>ng</strong>>syslog</stro<strong>ng</strong>>-<strong>ng</strong> <strong>Store</strong> <strong>Box</strong> can store log messages securely in encrypted,<br />

compressed, and digitally signed binary files. That ensures that any<br />

sensitive data is available only for authorized personnel who have the<br />

appropriate encryption key. Sections of the log files can be timestamped<br />

independently of other sections; timestamps can be requested from<br />

external Timestampi<strong>ng</strong> Authorities as well. The contents of the log files<br />

are indexed – terabytes of data can be browsed online. All data is stored<br />

on mirrored RAID devices to prevent data loss in case of hardware<br />

failure. Usi<strong>ng</strong> two SSB units in a high availability configuration is a<br />

simple and convenient way of ensuri<strong>ng</strong> continuous log collection.<br />

Licensi<strong>ng</strong> and support<br />

Buyi<strong>ng</strong> the <stro<strong>ng</strong>>syslog</stro<strong>ng</strong>>-<strong>ng</strong> <strong>Store</strong> <strong>Box</strong> (SSB) allows you also to download<br />

<stro<strong>ng</strong>>syslog</stro<strong>ng</strong>>-<strong>ng</strong> Premium Edition (PE) for every available platform and use<br />

it as the log collector agent of SSB. Software upgrades for one year –<br />

updates and fixes for both SSB and <stro<strong>ng</strong>>syslog</stro<strong>ng</strong>>-<strong>ng</strong> PE – are included in the<br />

base price. Hardware support covers full on-site support for the first<br />

year. Product support – includi<strong>ng</strong> 7x24 support – is available on an<br />

annual basis.<br />

Log collector agent for several platforms<br />

SSB uses the <stro<strong>ng</strong>>syslog</stro<strong>ng</strong>>-<strong>ng</strong> Premium Edition application to collect logs from<br />

different operati<strong>ng</strong> systems and hardware platforms, includi<strong>ng</strong> Linux,<br />

Unix, BSD, Sun Solaris, HP-UX, IBM AIX, IBM System i, as well as<br />

Microsoft Windows XP, Server 2003, Vista, and Server 2008.<br />

TO TEST THE SYSLOG-NG STORE BOX, REQUEST AN EVALUATION VERSION AT HTTP://WWW.BALABIT.COM/MYBALABIT/<br />

www.balabit.com

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!