Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
COMPANY
COMPANY CONFIDENTIAL
CONFIDENTIAL
LogRhythm 7 Focus
Customer Needs
LogRhythm 7 Innovation
Enterprise Scalability:
New back-end technologies at the log data layer increase
Consume and analyze ever
indexing rates, search performance, and provide full data
increasing volumes of data
replication via clustering
efficiently and reliably, fully
Independent scalability at data processing and indexing tiers
utilizing invested hardware for the
deliver improved performance and active/active massive scale
solution
deployments
General user interface enhancements supporting optimal
workflows when administering very large deployments (e.g.,
100K+ log sources).
System Monitor administration and configuration
enhancements, delivering low TCO for large agent
deployments (e.g., 100K+ agents).
Search: Simpler search
experience to enable greater
forensic efficiency when hunting
for and qualifying threats
Enterprise Scalability
COMPANY CONFIDENTIAL
Customer Impact
More efficiently delivers 100% indexed
solutions to ensure all data available
in rapid access search
Greater search performance and costeffective deployment resiliency
No loss of features and full access to
historical archive data
Superior architecture for massive
scale deployments more resilient,
more efficient.
Optimal benefit of LogRhythm 7
software architecture and inherent
hardware-based performance
improvements.
Collection
Security
Devices
Network
Devices
Applications,
Databases &
Servers
IndustrySpecific Devices
(SCADA, POS,
etc.)
COMPANY CONFIDENTIAL
System
Monitor &
Network
Monitor
Horizontal & vertical
scalability
Local caching
Generation
Unlogged
Endpoint
Activity
Unlogged
Network
Activity
Data Processor
Data Indexer
AI Engine
Active/Active HA
Horizontal & vertical
scalability
Max Processing Rate
up to 15,000 MPS
per node
Active/Active HA
Clustered scalability
Expandable storage
Max Indexing Rate
up
to 10,000 MPS per
node
Active/Passive HA
Horizontal & vertical
scalability
Max Processing
Rate up to 75,000
MPS per node
Processing
Persistence
Machine
Analytics
Platform
Manager
Active/Passive HA
Vertical scalability
Expandable storage
Managemen
t
Clustered Architecture
DC
DP
1 3
2 5
DX Cluster
COMPANY CONFIDENTIAL
3 1
4 6
Clustered Architecture
DC
DP
1 3
2 5
DX Cluster
COMPANY CONFIDENTIAL
3 1
4 6
5 2
6 4
Processor
Web
Web and
and
Client
Client
Console(s)
Console(s)
Dispatch
Columbo
Elasticsearch
Hermes
Local
Local
Browser
Browser
(for
(for now)
now)
Gomaintai
n
Grafana
COMPANY CONFIDENTIAL
Inside an
Indexer
Carpent
er
Config
Server
Confi
g
Files
Heart
Throb
Vitals
InfluxDB
Precision Search
COMPANY CONFIDENTIAL
Impact
Search precision to deliver targeted,
relevant results, reducing time
spent on analysis and search result
filtering
For example:
All logs categorized by LogRhythm as
Account Modify
Where Jacob.Franklins is the logged in
user
And the log includes the phrase
0120000340AB
No re-training or re-tooling
requiring, allowing teams to easily
take advantage of search precision
without ramp up time or reeducation.
COMPANY CONFIDENTIAL
Raw Log
Data
Data
Processo
r
Data
Collector
Normalized Date + Raw
Log Data
Log Data +
Contextualized
MetaData
COMPANY CONFIDENTIAL
Signed Log
Contextualiz
ed MetaData
Archives
AI Engine
Data
Indexer
Message Text
CharFilter
s
Tokenizer
Data
Process
or
Token
Filters
Analyzer
Contextualiz
ed Fields
Elasticsearch
Data Indexer
Raw message text is processed
through a series filters, enabling
quick performing key word searches
COMPANY CONFIDENTIAL
Resulting in a powerful
search experience for
precise, targeted search
results giving greater
efficiency to analysts
work flow
COMPANY CONFIDENTIAL
COMPANY CONFIDENTIAL
Innovations
Threat Map: real-time
geolocation threat display
Enhanced Risk-based Monitoring
& Analysis
Improved Risk Based Prioritization
(RBP)
List expiring values
Misc. Customer-driven Analytics
Enhancements
Dashboard Widget
A single view of the customers threat
landscape
COMPANY CONFIDENTIAL
COMPANY CONFIDENTIAL
Innovations
Impact
Evidence pinning
Case association
Case tags
Impact
Remote
SmartResponse
Execution
Manual Remote
Execution
Multiple Actions
Per Alarm
COMPANY CONFIDENTIAL
Each section contains detail endpoint forensics captured from the system
COMPANY CONFIDENTIAL
COMPANY CONFIDENTIAL
COMPANY CONFIDENTIAL
Improved System Monitor Agent Management reduces Overhead and enables increased scaling
Policy-Based Management
#2 Assign
to agents
#1 Build Your Template
COMPANY CONFIDENTIAL
COMPANY CONFIDENTIAL