Blog Entries

24. 07. 2019 Franco Federico Anomaly Detection, Log-SIEM, NetEye

Welcoming Elastic Stack X-Pack to NetEye 4

On June 13, we announced a new OEM Partnership with Elastic, and Elastic updated its relationship with OEM, MSP and CSP partners, with the result that in NetEye 4 we now have some new features. Starting with NetEye 4.6, you can now activate the X-Pack feature. After I activate X-Pack and open NetEye, I see:…

Read More
24. 07. 2019 Luca Buonocunto Log-SIEM, NetEye, Service Management

5 Bullet Points for Information Security Incident Management

Modern society has continued its increasing use of digital solutions, and today large amounts of sensitive data are stored digitally.  As the value and sensitivity of this information increases, the number of potential threats will increase accordingly. Verizon Enterprise’s RISK team recently published a report in cooperation with the United States Secret Service (USSS), the…

Read More
02. 07. 2019 Damiano Chini Log-SIEM, NetEye

Proxy Authentication with Grafana 6.2

Until now, authentication of NetEye users on Grafana was achieved by means of session cookies, which were provided by the Grafana server when authenticating in Icinga Web 2. However, with the upgrade of Grafana from version 5.2 to version 6.2, we can no longer employ this authentication procedure because Grafana has discontinued the use of…

Read More
28. 06. 2019 Michele Santuari Log Management

How to Debug NetEye Log Management

In a previous blog post I presented how the Log Management architecture fits in a NetEye cluster, and now I want to summarize my recent experiences to help you diagnose Elasticsearch health issues. Elasticsearch provides a set of APIs which help to identify and debug a number of potential causes. But NetEye Log Management is…

Read More
13. 06. 2019 NetEye Blog Admin Log-SIEM, NetEye

OEM Partnership with Elastic

Magic happens when collaboration really works and community spirit grows. This month, Würth Phoenix announced the expansion of its partnership with Elastic to make it faster and easier for users to deploy Elasticsearch within NetEye 4. Elastic is the company behind Elasticsearch, Kibana, Beats, and Logstash, an ecosystem of Open Source-based search and analytics tools….

Read More
30. 05. 2019 Franco Federico Log-SIEM

Beats and NetEye 4

NetEye 4 is composed of various modules, such as the NetEye 4 Log Manager that houses Elastic Stack with Search Guard. Our vision for the future of the NetEye 4 Log Manager is shown in the following diagram: Here you can see the various modules and technologies. For instance, you can see that we have…

Read More
22. 05. 2019 Tobias Goller APM, Cloud, Log Management, NetEye

Cloud Monitoring

The new challenge for monitoring solutions is to monitor infrastructure, software, and platforms that run in the cloud, or that are outsourced. The various contract models with cloud providers/outsourcers no longer focus on infrastructure monitoring, such as monitoring the fans or power supply in a physical server, but rather the availability and performance of applications,…

Read More
04. 04. 2019 Gianluca Piccolo Downloads / Release Notes, Log-SIEM, NetEye

Updated neteye, neteye-setup, elasticsearch-neteye-config, eventhandler and auditlog for NetEye 4.5

Updated neteye to version 4.5.1-1: Define neteye-cluster-local.target Updated neteye-setup to version 1.7.1-1: Manage target neteye single instance and cluster Update creation of icingaweb2 DB resource with dynamic creation of DB hostname Updated elasticsearch-neteye-config to version 1.5.0-1: Relate elasticsearch.service to neteye-cluster-local.target Updated eventhandler to version 1.7.6-1: Fix module DB hostname for cluster environment Updated auditlog to…

Read More
03. 04. 2019 Michele Santuari Log Management, NetEye

How to Manage Permissions in Log Analytics with NetEye 4

NetEye 4 Log Manager, as already presented in this blog post, allows you to easily manage the collection, navigation, visualization and analysis of large numbers of logs. For many reasons, I as a user may want to limit log access to a subset of users. For example a network administrator should only see the logs…

Read More
29. 03. 2019 Angelo Rosace Log Management, NetEye

Host Creation via Icingacli Commands for Monitoring and Deploying a Safed Agent Configuration

Creating hosts in NetEye’s Director module can sometimes be time-consuming and a repetitious, tiring and boring job. Especially if you have to populate Director with a large number of hosts for setting up a test environment, for example. One solution is to create a script consisting of nothing but icingacli commands. Each command line instruction…

Read More
25. 03. 2019 Oreste Attanasio Log Management, Log-SIEM, NetEye, Unified Monitoring

Safed improvements since 1.10.1

The Safed agent keeps track of the events it receives from the Eventlog by keeping the LastEventID in registry. At start time the agent tries to retrieve all events from Windows Eventlog since starting from the LastEventID. When the amount of events since LastEventID is too large or the LastEventID has been removed from the…

Read More
21. 03. 2019 Franco Federico Log-SIEM, NetEye

Field Anonymization with NetEye 4 for GDPR

The regulations of the GDPR in many cases require that some user data is not always present, and / and or that they are anonymized.  So I would like to show you now how NetEye 4 responds to this new requirement. NetEye 4 is composed of various modules. In the NetEye 4 Log Manager, we have Elastic…

Read More
20. 03. 2019 MarinovMihail Downloads / Release Notes, Log Management

Updated Safed Agent v1.10.1

– Retrieved events from eventlog (win 2008 +) starts from bookmark but should not be older than defined cache days

Read More
11. 03. 2019 Stefano Bruno Log-SIEM, NetEye

Segregated Multitenancy Monitoring: The Satellite and the Essential Role of the CA-Proxy

In many circumstances, monitoring systems need to be extended to locations where we have no direct control. We can think for instance of a company that provides monitoring services to various customers: each with its own firewalls and each with its own security rules. The deployment of firewall rules from the central monitoring node to…

Read More
07. 02. 2019 MarinovMihail Log-SIEM, NetEye

Secure Connections for the Safed Agent

The Safed agent can be configured via https and send its collected logs to the log collector though a TLS connection. The latest released version – 1.9.1 – supports TLS 1.2 (at a minimum) and TLS 1.3. The first step is to upload the private key, the local certificate and the CA certificate to the…

Read More

Archive