Professional Documents
Culture Documents
Made possible by
Thanks to
1
5/16/2017
System
Monitor
System
Monitor
System
Monitor
System
Monitor
System
Monitor
System
Monitor
System
Monitor
Preview of Key
Points
System
Monitor
Event
Subscription
Log
LogRhythm
Points Subscription
Event
Log
No inbound connections
or credentials requred
2
5/16/2017
Benefits of
WEC with LogRhythm supports WEC
LogRhythm LogRhythm Known Host works with WEC
3
5/16/2017
Add Log
Source to
System
Monitor for
each
Destination
Log
4
5/16/2017
Add Log
Source to
System
Monitor for
each
Destination
Log
5
5/16/2017
Log sources
Event
Subscription
Log
filtering Subscription
Event
Log
6
5/16/2017
Level 1 –
WEC
Subscription
Xpath filters
Level 2 –
Using Global
Log
Processing
Rules
RegEx
7
5/16/2017
Windows No management
How to manage multiple collectors?
Event Is WEC really working?
Collection is a Which computers are failing to forward security logs?
Are we missing any computers?
foundation Is my WEC collector overloaded?
Dropping events?
technology Unresponsive?
Approaching capacity?
How do I distribute load of many event sources between multiple
collectors?
8
5/16/2017
9
5/16/2017
Manage
subscriptions
consistently
across all
collectors
10
5/16/2017
Create custom
logs supported
by WEC in
seconds
Load balance
computers
between
collectors
11
5/16/2017
Optimize each
collector
automatically
to support
high volume
WEC
All settings
exposed via UI
At a glance
performance
and health
indicators
12
5/16/2017
3 ways to
measure
health
13
5/16/2017
www.logbinder.com
14