Educause Security Discussion mailing list archives

Re: SIEM Solutions


From: Debbie Montano <debbie () METAFLOWS COM>
Date: Fri, 15 Jun 2012 10:40:29 -0600

Another option...

MetaFlows offers Security-software-as-a-Service (SaaS), with a low monthly subscription rate.  MetaFlows Security 
System (MSS) provides SIEM &amp; log management, in MetaFlows secure cloud, plus an advanced network intrusion 
detection systems (IDS) and a rich forensic interface, providing full malware detection, prevention &amp; analysis.  
You can also get MetaFlows Security System as a fully managed service via MetaFlows partners.

(And going the other direction -- for the do-it-yourself-er's -- you can provision and run MetaFlows Security System on 
your own private infrastructure/servers, if you prefer.)

See: www.metaflows.com or contact me directly if you want additional info.

Debbie

Debbie Montano
MetaFlows, Inc
303 378 9762
debbie () metaflows com
www.MetaFlows.com




---- On Tue, 12 Jun 2012 14:11:37 -0600 Jeff Howlett &lt;howlettj () MEREDITH EDU&gt; wrote ---- 


We tried the AlienVault implementation at Meredith, but did not have 
the staff time to make it work like it should. Instead we went with a 
managed AlienVault system by Trusted Metrics www.trustedmetrics.com 
(they are the only US based certified AlienVault MMSP) and have been 
extremely happy. We have been running for 1.5 years with 24/7 support 
by Trusted Metrics and my staff loves the system. 
 
The cost is very reasonable, a little more than AlienVault pro, but 
monthly rather than in an unmanageable (for us) cost directly to 
AlienVault for the software license and without the training costs and 
time for my engineers. I would highly recommend anyone looking into a 
SIEM to check into the MMSP model. 
 
Feel free to contact me with any questions. 
 
Jeff 
 
_________________________ 
Jeffrey R. Howlett 
Chief Information Officer 
Meredith College 
3800 Hillsborough Street 
Raleigh, NC 27607 
howlettj () meredith edu 
Phone: (919) 760-8828 
Fax: (919) 760-2325 
 
 
On Tue, Jun 12, 2012 at 3:04 PM, Shawn Kohrman &lt;skohrman () apu edu&gt; wrote: 
&gt; Matthew, 
&gt; Here are the total responses I've received. 
&gt; 
&gt; Shawn 
&gt; ----- 
&gt; Shawn A. Kohrman, Security Architect 
&gt; 
&gt; Azusa Pacific University 
&gt; Information &amp; Media Technology 
&gt; 901 E. Alosta Ave., PO Box 7000 
&gt; Azusa, CA 91702-7000 
&gt; 
&gt; P:  626.815.2054 | F:  626.815.2061 | http://www.apu.edu/ 
&gt; ----- 
&gt; 
&gt; 
&gt; 
&gt; On Wed, Jun 6, 2012 at 8:44 PM, Matthew Hodgett &lt;m.hodgett () qut edu au&gt; 
&gt; wrote: 
&gt;&gt; 
&gt;&gt; Shawn, 
&gt;&gt; 
&gt;&gt; I was hoping to see some of the responses myself. We have been using a 
&gt;&gt; syslog server as a forensic store for many years, and diverting information 
&gt;&gt; to a SEIM for live analyses. Both of these systems can also collect data 
&gt;&gt; directly that would otherwise be missing. The time is right for us to 
&gt;&gt; re-assess our situation and are interested to hear what others are doing. 
&gt;&gt; 
&gt;&gt; Regards 
&gt;&gt; Matthew 
&gt;&gt; 
&gt;&gt; 
&gt;&gt; On 06/06/12 09:33, Shawn Kohrman wrote: 
&gt;&gt;&gt; 
&gt;&gt;&gt; Many thanks to all of you who responded!  I'll keep you posted as we move 
&gt;&gt;&gt; forward. 
&gt;&gt;&gt; 
&gt;&gt;&gt; Shawn 
&gt;&gt;&gt; ----- 
&gt;&gt;&gt; Shawn A. Kohrman, Security Architect 
&gt;&gt;&gt; 
&gt;&gt;&gt; Azusa Pacific University 
&gt;&gt;&gt; Information &amp; Media Technology 
&gt;&gt;&gt; 901 E. Alosta Ave., PO Box 7000 
&gt;&gt;&gt; Azusa, CA 91702-7000 
&gt;&gt;&gt; 
&gt;&gt;&gt; P:  626.815.2054 | F:  626.815.2061 | http://www.apu.edu/ 
&gt;&gt;&gt; ----- 
&gt;&gt;&gt; 
&gt;&gt;&gt; 
&gt;&gt;&gt; 
&gt;&gt;&gt; On Tue, Jun 5, 2012 at 8:52 AM, Paul Hanson &lt;paulh () haas berkeley edu 
&gt;&gt;&gt; &lt;mailto:paulh () haas berkeley edu&gt;&gt; wrote: 
&gt;&gt;&gt; 
&gt;&gt;&gt;    We're currently evaluating the community edition of Alienvault since 
&gt;&gt;&gt; it supports ossec, syslog, arpwatch, p0f, and snort.  There are a plethora 
&gt;&gt;&gt; of other products it supports but those are the big hitters.  I've heard the 
&gt;&gt;&gt; professional version is leaps and bounds above the free version but haven't 
&gt;&gt;&gt; gotten that far. 
&gt;&gt;&gt; 
&gt;&gt;&gt;    In terms of alternatives I've heard good things about 
&gt;&gt;&gt;    IBM QRadar (formerly Q1 Labs) 
&gt;&gt;&gt;    Tenable Log Correlation Engine 
&gt;&gt;&gt;    Solarwinds Log &amp; Event Manager (formerly Trigeo) 
&gt;&gt;&gt; 
&gt;&gt;&gt;    Cheers! 
&gt;&gt;&gt;    Paul 
&gt;&gt;&gt; 
&gt;&gt;&gt; 
&gt;&gt;&gt;    -----Original Message----- 
&gt;&gt;&gt;    From: The EDUCAUSE Security Constituent Group Listserv 
&gt;&gt;&gt; [mailto:SECURITY () LISTSERV EDUCAUSE EDU 
&gt;&gt;&gt; &lt;mailto:SECURITY () LISTSERV EDUCAUSE EDU&gt;] On Behalf Of Shawn Kohrman 
&gt;&gt;&gt;    Sent: Monday, June 04, 2012 2:49 PM 
&gt;&gt;&gt;    To: SECURITY () LISTSERV EDUCAUSE EDU 
&gt;&gt;&gt; &lt;mailto:SECURITY () LISTSERV EDUCAUSE EDU&gt; 
&gt;&gt;&gt;    Subject: [SECURITY] SIEM Solutions 
&gt;&gt;&gt; 
&gt;&gt;&gt;    Hello, 
&gt;&gt;&gt;    I am currently working on a proposal for implementing a central 
&gt;&gt;&gt; logging system for our various services/devices.  I was wondering if I 
&gt;&gt;&gt; should be looking for a SIEM solution to consolidate event correlation with 
&gt;&gt;&gt; log management. 
&gt;&gt;&gt; 
&gt;&gt;&gt;    I'm curious to know what others have done or are planning in this 
&gt;&gt;&gt; area. 
&gt;&gt;&gt; 
&gt;&gt;&gt;    Shawn 
&gt;&gt;&gt; 
&gt;&gt;&gt;    ----- 
&gt;&gt;&gt;    Shawn A. Kohrman, Security Architect 
&gt;&gt;&gt; 
&gt;&gt;&gt; 
&gt;&gt;&gt;    Azusa Pacific University 
&gt;&gt;&gt;    Information &amp; Media Technology 
&gt;&gt;&gt;    901 E. Alosta Ave., PO Box 7000 
&gt;&gt;&gt;    Azusa, CA 91702-7000 
&gt;&gt;&gt; 
&gt;&gt;&gt;    P: 626.815.2054 &lt;tel:626.815.2054&gt; | F: 626.815.2061 
&gt;&gt;&gt; &lt;tel:626.815.2061&gt; | http://www.apu.edu/ 
&gt;&gt;&gt;    ----- 
&gt;&gt;&gt; 
&gt;&gt;&gt; 
&gt;&gt; 
&gt;&gt; -- 
&gt;&gt; Matthew Hodgett, MInfTech, CISSP 
&gt;&gt; IT Security Engineer | Queensland University of Technology 
&gt;&gt; Phone: (07) 313 89454 | Fax: (07) 31382921 
&gt;&gt; 
&gt;&gt; QUT Classifications, refer MOPP F/1.2.5 
&gt;&gt; CRISCO No. 00213J 
&gt; 
&gt; 



Current thread: