Updated Safed Agent v1.10.1
– Retrieved events from eventlog (win 2008 +) starts from bookmark but should not be older than defined cache days
Read More– Retrieved events from eventlog (win 2008 +) starts from bookmark but should not be older than defined cache days
Read MoreWith the release of NetEye 4, we have also redesigned the Log Management module. In this blog post I would like to briefly discuss the main innovations and improvements in NetEye 4 Log Management. First, the management and configuration interface of NetEye 4 Log Manager appears in the unified NetEye 4 layout. Basically, it has…
Read MoreThis blog post describes the basic architecture of an Elasticsearch cluster. The deployment of a cluster is needed to provide high-availability and, whenever possible, to increase performance. NetEye 4’s clustering service is based on RedHat 7’s High Availability Clustering technologies: Corosync: Provides group communication between a set of nodes, application restart upon failure, and a quorum…
Read MoreWhen you need to manage and collect large amounts of data, there can be a lot of hard tasks to do. So we decided to take some of the best Open Source tools to help us do it in the best possible way. Let me introduce you to Rsyslog and the Elastic Stack implementation for…
Read MoreReady to take your IT process skills beyond the traditional? Our new training offerings will help you acquire, maintain and improve your knowledge and skills around our solutions. This year’s training program contains courses for NetEye, EriZone or Alyvix customers and partners, each lasting between 2 and 4 working days. The main focus will be…
Read MoreSuppose you have an OpenLDAP Server and you want to analyze what it does. A good way to do this is to send the logs to NetEye’s LogServer. Some elements you will see include: – Returned Entries! (ENTRY) – Search Operations! (SEARCH) – Total Connections! (BIND) To do this you need to add a new…
Read MoreIf you have an Elasticsearch Database like the one in the NetEye Elastic Stack Module then you are surely interested in integrating this information into your Monitoring environment. To do this, use this new plugin: check_elasticsearch_query # /data/neteye/usr/lib/nagios/plugins/local/check_elasticsearch_query –help Check a count of number of events fount in elasticsearch over a query and timeframe Usage:…
Read MoreIn this post, and in the one that will follow in the next weeks, I would like to analyze the role of IT Asset Management in adapting to the new General Data Protection Regulations (GDPR). In this first article I will briefly introduce what the GDPR is, what measures it introduces, and how the IT…
Read MoreDo you use Cisco’s network infrastructure? Would you like to view its logs through the syslog protocol in an Elasticsearch database? Find out below about the filters and templates needed for the Logstash setup. As you probably already know, you need a Logstash instance in order to get indexed data into the Elasticsearch database. Cisco…
Read MoreKeeping an offline copy of your logs does not only provide better visibility from the system management point of view, but also turns out to be extremely precious in case of a security incident during which your local copies have been affected. As many of you might know, the Log Management module of NetEye offers…
Read MoreDuring my last projects I noticed that the implementation of a „Security Operations Center“ (in short SOC) is becoming increasingly important, especially for our enterprise customers. Mainly for big companies that are of public interest like banks, energy providers, assurances etc. the topic of cyber threats is getting more actual and requires special attention. This…
Read MoreSome time ago I published an article about how to store the NetEye SMS Protocol log into an ELK environment. Now, after using it some times, I discovered that it was not completely correct as the time/date functions for the Logstash filters are a bit more complicated. In particular, it was that the date was…
Read MoreSometimes it is not so visible how many SMS are sent by a NetEye Server and to whom. So it could be a good idea to give the sms-send-protocol file to the Log Management and to include it into the Elasticsearch Index. Then you may create a Dashboard in Kibana to show the usage of your…
Read MoreAs you already know, from version 3.6 we’ve integrated the Elastic Stack (consisting of Elasticsearch, Logstash and Kibana) to the NetEye Log Management. This integration provides a lot of additional possibilities for log analysis, log correlation, dashboard creations, etc. Furthermore, it allows to store the collected logs for different periods, which wasn’t possible on prior…
Read MoreThanks to the integration of the Elastic Stack to our NetEye Log Management, we established a professional relationship to Elasticsearch BV. Today we are very proud to announce that the history behind our NetEye Log Management was published on the official Elastic blog. Our business unit manager Georg Kostner, describes the market requirements, which led us to the development…
Read More