Featured post

Using Splunk with syslog-ng
Tuesday, May 21, 2013 @ 01:05 PM Author: James Luby

Our customers often ask us how syslog-ng can be used with various log analysis tools. One of those tools is Splunk, a popular search and analysis platform. Many users of Splunk also have syslog-ng deployed in their environments. We have created a technical guideline that describes some scenarios in which users can benefit from syslog-ng Premium Edition’s features and offers some technical guidance, including configuration examples, to optimize the syslog-ng configuration. There are five use cases for using syslog-ng with Splunk which are often cited by our customers. Our latest guide goes into detail about these use cases and shows some example configuration files to get you started. First, collecting and centralizing log messages from network devices such as routers is one of the most common deployments of syslog-ng with Splunk. Major router manufacturers like Cisco and Juniper use the syslog protocol to transfer log messages. syslog-ng natively supports the original syslog protocol RFC3164 and the new syslog protocol RFC5424. In addition, syslog-ng also supports variants of these protocols which are used by certain router manufacturers. Secondly, many organizations that deploy Splunk have existing log management and analysis tools. Some departments within the same company, such as the Network Operations group and the IT security group, may have use for the same data but prefer to use different analysis tools such as Security Information and Event Management (SIEM) solutions. In these environments, syslog-ng is often used to collect and aggregate log messages and then forwarded to multiple destinations including a Splunk ... [Read More]

PRESS

Industrial Innovation Grand Prize for BalaBit’s Shell Control Box
Saturday, March 23, 2013 @ 11:03 AM Author: Andrea Ipolyi

BalaBit has received two awards from eight categories in the annual Innovation Grand Prize competition in Hungary, for “developing the next generation of activity monitoring tools”. The jury of the ... [Read More]
Real-time prevention of the most costly cyber-attacks with BalaBit’s Shell Control Box
Tuesday, February 12, 2013 @ 03:02 PM Author: Andrea Ipolyi

The new real-time alerting and blocking feature of Shell Control BoxTM 3 F4 activity monitoring appliance prevents malicious user activities, either external or internal, even those initiated by users with ... [Read More]