Introduction To LogRhythm and Its Components

You might also like

Download as pptx, pdf, or txt
Download as pptx, pdf, or txt
You are on page 1of 15

Introduction to

LogRhythm &
Components
LogRhythm v/s Other SIEMS

• Intuitive Co-relation Building


Blocks.

• Powerful anomaly detection


capabilities.

• It does better event


classification.

• Host and network monitoring


2
capabilities.
Data Flow in LogRhythm

3
Component: System Monitor

▪ System Monitor Pro


4
▪ System Monitor Lite
Component: Data Processor

 Log Storage
5
 Active Archive
 Inactive Archive
Component: Data Processor

Services
 Mediator
 Storage
 Forwarding

 Message Processing Engine (MPE)


 Log Identification
 Log Classification
 Event Processing ( RBP)
 Metadata Processing
6
Component: Data Indexer

7
Component: Platform Manager

8
Component: Platform Manager

Services:

 Job Manager Service

 Alarming, Reporting, and Response Manager (ARM) Service

9
Component: AI Engine

10
Component: Client Console

11
Component: Web Console

12
Life of a Log in LogRhythm

13
Architecture

14
Q&A

You might also like