Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Event Log Management Solution for Sarbane Oxley

Posted on 2004-10-29
6
Medium Priority
?
226 Views
Last Modified: 2013-12-03
I am the coordinator of Sarbane Oxley audit in my company, and looking for Event log management solution to keep track all my windows log files and Unix syslog. I found that most of the event management software available in the market are Windows-centric, and able to find one with both, which is "Event Tracker from Prism Microsystem". My question is any other product available in the market that can serve both Windows and Unix?
0
Comment
Question by:belim
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
6 Comments
 
LVL 4

Expert Comment

by:tmcguiness
ID: 12449600
We use Dorian which is WinCentric but is very good too.

I have heard very good things about Kiwi http://www.kiwisyslog.com/ I'd take a look at them.

Event Log Manager (ELM) is another product that I'm not very familiar with. It seems like when I was researching, it lacked features, but that's been a while & I could be remembering wrong so you could take a look.

Another consideration would be to put a syslog daemon on your winders machines and then use your *nix syslog and reporting mechanisms. The only caveat I have there is that I think you would still need to archive your windows logs in .evt. If you ever needed to prosecute somebody, the reformatted messages may not be admissable as evidence in court. It should be fine for general audit types of purposes though.

The last caveat I have is that I once had a syslog-like utility (Kane Secure Enterprise) and it would suck the logs off the machines in realtime. So if somebody was trying to figure out a problem, they could be trying to look at the error logs locally and they would instead see them scrolling off the screen. Then we'd have to go to the KSE monitor and sort through logs to find what we wanted. So anyway, just be careful because as important as logs are to you in your mission, they can be equally important to others in theirs.

Good Luck!

todd
0
 

Author Comment

by:belim
ID: 12449852
I am looking for Enterprise solution.KiwiSyslog is too simple, i am looking for something that can fulfill 4 processes, they are Collect, Store or Archive, Analyse, and report.
0
 
LVL 7

Accepted Solution

by:
shahrial earned 600 total points
ID: 12450326
> My question is any other product available in the market that can serve both Windows and Unix?
Not that I know of but your can customise. Below are some links to resources.

syslog Client Configs for Windows/Non-UNIX
http://www.loganalysis.org/sections/syslog/windows-to-syslog/

Logging via Syslog
http://www.practicallynetworked.com/support/syslog.htm

Hope it's useful...;-)
0
 
LVL 7

Expert Comment

by:shahrial
ID: 12450333
Here's another arcticle which may be useful for you.

How to Monitor Windows NT from Unix
http://www.aplawrence.com/Reviews/NTSyslog.html
0

Featured Post

Looking for the Wi-Fi vendor that's right for you?

We know how difficult it can be to evaluate Wi-Fi vendors, so we created this helpful Wi-Fi Buyer's Guide to help you find the Wi-Fi vendor that's right for your business! Download the guide and get started on our checklist today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Check out what's been happening in the Experts Exchange community.
What we learned in Webroot's webinar on multi-vector protection.
Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

610 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question