syslog-ng Store Box - BalaBit
syslog-ng Store Box - BalaBit
syslog-ng Store Box - BalaBit
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
CENTRAL LOG SERVER FOR HETEROGENEOUS ENVIRONMENTS<br />
■ Central logserver appliance<br />
■ Complete log-lifecycle management<br />
■ Encrypted, signed, and timestamped log storage<br />
■ Web-based configuration interface and log search<br />
■ Log collector agent for Windows, IBM System i and<br />
Unix-variant hosts<br />
<stro<strong>ng</strong>>syslog</stro<strong>ng</strong>>-<strong>ng</strong> <strong>Store</strong> <strong>Box</strong><br />
trusted log collection and storage<br />
■ Fast search capability via log message indexi<strong>ng</strong><br />
■ Forward logs to external database or SIEM devices<br />
■ Up to 10 Terabytes of effective disk space<br />
■ Collect more than 100,000, and index more than<br />
75,000 log messages per second real-time<br />
Are you looki<strong>ng</strong> for a simple way to store your logs in one place? Do you need to prevent unauthorized access to<br />
your logs? Do you need a reliable platform with excellent hardware support and high availability? Is your loggi<strong>ng</strong><br />
infrastructure subject to policy compliance?<br />
Built around the popular <stro<strong>ng</strong>>syslog</stro<strong>ng</strong>>-<strong>ng</strong> application used by thousands of organizations worldwide, the <stro<strong>ng</strong>>syslog</stro<strong>ng</strong>>-<strong>ng</strong> <strong>Store</strong> <strong>Box</strong><br />
(SSB) bri<strong>ng</strong>s you a powerful, easy to configure appliance to collect and store your logs. SSB allows you to collect, process,<br />
and store log messages from a wide ra<strong>ng</strong>e of platforms and devices.<br />
www.balabit.com
Secure, reliable log transfer<br />
The <stro<strong>ng</strong>>syslog</stro<strong>ng</strong>>-<strong>ng</strong> <strong>Store</strong> <strong>Box</strong> collects and classifies log messages from a<br />
wide variety of devices and applications and can receive log messages<br />
sent usi<strong>ng</strong> both the legacy BSD-<stro<strong>ng</strong>>syslog</stro<strong>ng</strong>> protocol, as well as the latest<br />
<stro<strong>ng</strong>>syslog</stro<strong>ng</strong>> protocol standards. Transferri<strong>ng</strong> messages to SSB is supported<br />
usi<strong>ng</strong> the UDP, TCP, and TLS protocols. Mutual authentication of the<br />
TLS- encrypted channels maintains the integrity and confidentiality of<br />
transferred information. Usi<strong>ng</strong> <stro<strong>ng</strong>>syslog</stro<strong>ng</strong>>-<strong>ng</strong> to transfer the log messages<br />
helps you avoid losi<strong>ng</strong> messages even in case of network or hardware<br />
errors.<br />
Web-based configuration and access<br />
SSB can be conveniently configured from a browser usi<strong>ng</strong> a simple,<br />
clean user interface. Logs, includi<strong>ng</strong> logs stored remotely on a remote<br />
backup server, are also accessible and can be browsed from the SSB<br />
interface. SSB also features highly customizable access control –<br />
you can specify exactly who has access to certain parts of the SSB<br />
configuration, or to log messages. User groups and privileges can be<br />
retrieved from your LDAP server (e.g., from Microsoft Active Directory).<br />
Configuration cha<strong>ng</strong>es are automatically logged.<br />
Handle extreme load<br />
The <stro<strong>ng</strong>>syslog</stro<strong>ng</strong>>-<strong>ng</strong> <strong>Store</strong> <strong>Box</strong> is optimized for performance, and can handle<br />
enormous amount of messages. Dependi<strong>ng</strong> on its exact configuration,<br />
it can collect over 100,000 messages per second, and index over<br />
75,000 messages per second, and process over 35 GB of raw logs per<br />
hour. Larger versions of the appliance are capable of stori<strong>ng</strong> up to 10<br />
Terabytes of data.<br />
Direct database access<br />
SSB natively supports SQL database sources allowi<strong>ng</strong> users to fetch log<br />
messages directly from MySQL, Microsoft SQL (MSSQL), Oracle, and<br />
PostgreSQL databases. In addition to stori<strong>ng</strong> messages locally on SSB,<br />
log messages can be transferred directly to SQL databases.<br />
Trusted, timestamped log storage<br />
The <stro<strong>ng</strong>>syslog</stro<strong>ng</strong>>-<strong>ng</strong> <strong>Store</strong> <strong>Box</strong> can store log messages securely in encrypted,<br />
compressed, and digitally signed binary files. That ensures that any<br />
sensitive data is available only for authorized personnel who have the<br />
appropriate encryption key. Sections of the log files can be timestamped<br />
independently of other sections; timestamps can be requested from<br />
external Timestampi<strong>ng</strong> Authorities as well. The contents of the log files<br />
are indexed – terabytes of data can be browsed online. All data is stored<br />
on mirrored RAID devices to prevent data loss in case of hardware<br />
failure. Usi<strong>ng</strong> two SSB units in a high availability configuration is a<br />
simple and convenient way of ensuri<strong>ng</strong> continuous log collection.<br />
Licensi<strong>ng</strong> and support<br />
Buyi<strong>ng</strong> the <stro<strong>ng</strong>>syslog</stro<strong>ng</strong>>-<strong>ng</strong> <strong>Store</strong> <strong>Box</strong> (SSB) allows you also to download<br />
<stro<strong>ng</strong>>syslog</stro<strong>ng</strong>>-<strong>ng</strong> Premium Edition (PE) for every available platform and use<br />
it as the log collector agent of SSB. Software upgrades for one year –<br />
updates and fixes for both SSB and <stro<strong>ng</strong>>syslog</stro<strong>ng</strong>>-<strong>ng</strong> PE – are included in the<br />
base price. Hardware support covers full on-site support for the first<br />
year. Product support – includi<strong>ng</strong> 7x24 support – is available on an<br />
annual basis.<br />
Log collector agent for several platforms<br />
SSB uses the <stro<strong>ng</strong>>syslog</stro<strong>ng</strong>>-<strong>ng</strong> Premium Edition application to collect logs from<br />
different operati<strong>ng</strong> systems and hardware platforms, includi<strong>ng</strong> Linux,<br />
Unix, BSD, Sun Solaris, HP-UX, IBM AIX, IBM System i, as well as<br />
Microsoft Windows XP, Server 2003, Vista, and Server 2008.<br />
TO TEST THE SYSLOG-NG STORE BOX, REQUEST AN EVALUATION VERSION AT HTTP://WWW.BALABIT.COM/MYBALABIT/<br />
www.balabit.com