This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Looking for an recommendation: Logfile management / SIEM

Hi all,

 

to make it short: Im looking for a alternative solution to splunk. From time to time we have to create rulesets, based on captured traffic. As a result we often have huge logfiles and need to analyse them or to have to create a ruleset from them. We have textfiles up to 3GB and excel and access are not working with these filesizes. Normally Excel would be sufficient for me, if it could handle alle the data....

Are there any (simple) products (preferable opensource) that can be used to import and analyse textfiles? It would also be good, if the tool could simplyfy the data (remove duplicates etc) and create sth. like a connection overview with custom selects.

 

 

 

Best Regards

Sebastian



This thread was automatically locked due to age.
Parents Reply Children
  • Hi,

    I would say, it doesn´t matter what kind of product to use. I think it could be either a product that can handle netflow information or syslogs. Netflow also adds the amount of data, but for my purpose, to define firewall rules, both options would be sufficient. Afaik one benefit with netflow is, that you can immediately see, wheter it is a finished connection and if it is a connection start or teardown.

     

    We already use solarwinds, but I think it is pretty lazy and not really responsive. As you log quite a huge amount of data, it becomes even more slowly. It is also not easy to export the logged data, when we speak about a timeframe that is more than 10 minutes.

     

    I think I will need to make some tests with different products to get an impression, what I need.