Raz-Lee Security Inc., a major vendor of security, auditing and compliance software solutions for IBM i systems, announces the availability of extended Syslog for SIEM support.
Following are some of the highlights of the extended support:
- Field-mode formats for IBM QRadar (LEEF) and HP ArcSight (CEF) are supported; each event value is stored in a separate field together with its appropriate descriptive name. Previous support for LEEF/CEF and other standards, with messages that integrate field values within a descriptive message, were preserved. It should be noted that Raz-Lee is certified by IBM as “Ready for Security Intelligence” and partnered with Q1Labs prior to their acquisition by IBM.
- As more and more companies worldwide are using multiple SIEM solutions, RazLee now supports up to 3 SIEM products/servers simultaneously. For example, iSecurity can send network and system related alerts to one SIEM product/server and application-related alerts to a second SIEM server. In addition, we support Imperva SecureSphere DAM and McAfee DAM and ESM (SIEM) products.
- Each of the supported SIEM products/servers is defined by its own unique destination IP, Port, CCSID, message filtering, etc.
- LEEF/CEF field mode support sends only meaningful fields. For example, since Move and Rename objects have the same Audit Type but different subtypes, the fields sent will be those relevant to the activity to the object.
- UDP, TCP and encrypted TLS protocols are all supported.
- Advanced communications recovery features have been implemented where feasible, in the event of network problems or SIEM unavailability.
The extended Syslog support capabilities and features are a direct result of increasing customer demand for integrating IBM i (AS/400) security-related event alerts with SIEM solutions.
"Raz-Lee is excited to be able to offer the market advanced Syslog capabilities which supplement our existing partnerships, such as our DB/400 Agent for Imperva SecureSphere and our McAfee-certified DAM (database activity monitoring) and ESM (SIEM) solutions” said Shmuel Zailer, CEO at Raz-Lee Security. "The proven integration of all iSecurity solutions with products from IBM, HP, Splunk, Juniper, RSA, GFI, NTT, CA and others once again establishes Raz-Lee’s position at the leading edge of IBM i technology.”
LATEST COMMENTS
MC Press Online