Download as pptx, pdf, or txt
Download as pptx, pdf, or txt
You are on page 1of 22

ArcSight Data Platform - Logger

Technical Presentation Training, Level 320

Technical Field Enablement

September 2018
 What is Logger?
 Standalone Logger
 ArcSight Data Platform – ADP Logger
 Logger Components & Architecture
 Logger Value Proposition
 Competition
 Why Logger?
What is Logger?

What is Logger ?

 ArcSight Logger is a Universal Log Management solution that can Collect

Everything, Analyze Anything and can be Used Anywhere.
 ArcSight Logger unifies searching, reporting, alerting and analysis across
ANY type of enterprise log data.
 ArcSight Logger supports multiple deployment options and can be
installed as an Appliance or as Software on a physical or virtual machine.
 Supports Cyber Security, Compliance, IT Operations, GRC, and Log
Analytics. Logger is not just a security tool!
 Key piece in a security portfolio for long term high-integrity event
archiving and reporting
What is Logger ?
In ADP, Logger consumes
events from Event Broker

In standalone mode,

Enterprise Hunt Data Third Party

User Behavior
Security Tools Lake Applications
consumes events from Management

Connectors and direct L L L L


ArcSight Data


Quick Searches and Event Broker

Reports on years of data

Compliance, GRC, IT Ops,
Security Use Cases

12 TB addressable storage Data
Cloud Servers & Network Endpoint
Users Apps
per node Workloads loT

Scalable up to 100 peers

Standalone Logger and ADP Logger

Standalone Logger and ADP Logger

 Same code, same features, just licensed differently

 All Loggers are licensed on GB of events ingested per day

 Standalone Logger
 Used without ADP
 Can consume events from raw devices or Connectors

 ADP Logger
 Consumes events from raw devices, Event Broker or from Connectors
 Consumption license centrally managed by ArcMC
Logger Components & Architecture

Logger Components
 Receivers
 Receives events from SmartConnectors, FlexConnectors, Files, Network Connections
 ADP Logger can also receive events from Event Broker
 Forwarders
 Forwards events to ArcSight ESM, other Connectors, other Syslog or any TCP or UDP downstream device
 Storage Groups
 Allow for the separation of events by retention period or by event type
 Search
 Google-like search for events, over time, use pipeline operators for transformations and quick charts
 Dashboards
 Visual summaries of activity over time, top entities
 Reports
 Repeatable, ad-hoc or scheduled, long term analysis and summary of events suitable for Management as well
as Analysts
 Lookups
 Dynamic comparisons with external sources of information, such as a list of malicious domains or blacklist IP
 Alerts
 Both near real time and scheduled
Quick time to value through log analysis and
 Take advantage of
ArcSight CEF Categories
to quickly build powerful
 All failed login attempts
across ANY device in your
organisation is as simple as
-categoryBehavior =
"/Authentication/Verify" AND
categoryOutcome = "/Failure"
 Logger easily turns your
searches in to
meaningful dashboards
used across your
120+ Searches, Filters and Reports Included
Dozens of search filters and
reports allow you to immediately
analyse and deliver quality
dashboards and reports within

Can be extended with

Compliance Packages such as

Easily build your own content

and share within the enterprise

Storage Groups
 Up to 100 Storage Groups help segregate data with different access rights, retention
and priority
 Store highest priority events online for a longer period of time
 Prioritize storage so disk cost is reduced and optimised

Scheduled and Real Time Alerts
 Be alerted in near-real time as
soon as a critical event occurs, such
as “A USB storage key was inserted
in to a critical server”

 Scheduled alerts allow for alerting

on single or multiple occurrences
over time, such as “Too many
failed login attempts to critical
assets in the last hour”

 Alerts can be actioned in Logger or

sent to other ArcSight components,
SNMP destinations and other
Syslog destinations

Quick Searches
 Searches can be free text like
 Start with a simple search and let
Logger help you define your next
search or pivot
 Turn a search in to a visualisation

ArcSight Data Platform Logger
Secure Data Integration
 Micro Focus Secure
Data provides Format-
Preserving Encryption
 ArcSight
SmartConnectors apply
the FPE to one or more
 ArcSight Logger
provides on-demand
clear/FPE display, with
access defined by Role
Logger Value Proposition

Logger Value Proposition
 Straightforward event consumption for both standalone and
 Long term storage
 Quick search – google like search across fields and any text.
 Bloom filters allow unmatched speed across billions of events.
 Repeatable Reporting
 Scalable Performance, up to 12 TB per instance, and up to 100
peers. Log Management that scales.
 Typically less-expensive longer term storage thanks to high
levels of compression (around 7:1 – 10:1)
 Peer based searching allows transparent scale out without
operational disruption
 NIST 800 Compliant log archiving to NAS, DAS or any medium
with no time limit.
 Archive and hash digest all events to guarantee event integrity
 Granular Role Based Access – only the right people can see
sensitive information

 Splunk
 Multiple Splunk Data Models with varying normalization make Big Data analysis near-impossible
 More Expensive. Even more so as data volumes grow. Filtering & Aggregation are difficult and problematic.
 Poor Compliance solution – allows for deletion of events in data store
 LogRhythm
 Appliance-only offering
 Limited device support
 Custom log sources hard to support
 Elastic
 Takes a lot of time to configure and structure data (build your own filters)
 Fine grained JSON, XML and programming skills required to deliver near-Logger quality dashboards and
 Is a plethora of applications, widgets and configuration files (Elastic, Kibana, Logstash and many plugins such
as GROK)
Sizing and Capacity
 Software Logger
 5 GB / day minimum, steps of 5 GB/day up to 500 GB/day
 Appliance Logger
 L7600 5 GB / day minimum, steps of 5 GB/day up to 250 GB/day
 12 TB Addressable Storage per Logger instance
 Can mix and match peering to software and appliances
 Up to 100 peers – transparent searching across all peers
 High availability can be achieved by using
 Logger destination pools (from Smart Connector)
 HA appliances can be used to ingest a second copy of all events in case of primary failure

Why Logger ?
 ArcSight Logger is a Universal Log
Management solution that can Collect
Everything, Analyze Anything and can

be Used Anywhere. ArcSight

Enterprise Hunt Data Third Party

User Behavior
Security Tools Lake Applications
 ArcSight Logger unifies searching, Management
reporting, alerting and analysis across
ANY type of enterprise log data. L L L L

ArcSight Data

ArcSight Logger supports multiple


deployment options and can be Event Broker
installed as an Appliance or as
Software or as a Virtual Machine.
 Supports Cyber Security, Compliance,
IT Operations, GRC, and Log Analytics

 Plays a key role in high-integrity long-
term event archiving and reporting Data
Servers &
within the ArcSight Data Platform Users Cloud Apps
Network Endpoint loT

Thank you.

For more information, visit the

Sales or Partner Portal.
Make sure to fill out your
survey after the course!


You might also like