Showing posts with label loglogic. Show all posts
Showing posts with label loglogic. Show all posts

Thursday, September 23, 2010

Two Fun Presentations Today

Just FYI, I am doing two fun PCI DSS presentations today:

#1 LogLogic’s PCI 2.0 - What's Next? (register)

The PCI DSS standard is evolving, with version 2.0 due some time very soon. The summary of changes has just been issued. Do you know how it affects you?  Dr Anton Chuvakin, author of the book “PCI Compliance: Understand and Implement Effective PCI Data Security Standard Compliance” will talk us through what’s expected, how you should respond, and how you should target your efforts. The focus of course will be on audit trails, tracking and forensics within a best-practice framework provided by LogLogic.

and

#2 BrightTalk’s  What PCI DSS  Taught Us  About Security (register)

This presentation will derive some useful lessons from our industry experience with PCI DSS. Organization can use these lessons to improve their security programs and reduce risk as well.

The first one is more useful and the second one is more … fun!

Enjoy!

Possibly related posts:

Enhanced by Zemanta

Tuesday, September 07, 2010

Log Standards and Future Trends

As some of you know, I’ve done this BrightTalk Log Management web conference the other week. My presentation was about “Log Standards and Future Trends.” Here is an embed of my presentation with voice.  If you just want this slides, go check the Slideshare version.

A BrightTALK Channel
Enjoy!
Possibly related posts:

Thursday, July 29, 2010

Log Awesomeness – On August 19!

As far as awesomeness is concerned  [and I am a big student of it :-)], this is full of it. BrightTalk Log Management Summit promises to be as awesome as logging events go... Here is an agenda:

WHEN: Thursday, August 19, 2010, attend live online throughout the day or afterward on-demand

HOW: Register Now: http://www.brighttalk.com/r/vbf

TOPICS AND PRESENTERS:

  • “Log Standards & Future Trends” by Dr. Anton Chuvakin, Principal, Security Warrior Consulting
  • “Leveraging Logs, Information and Events” by Derek Brink, VP & Research Fellow for IT Security, Aberdeen Group
  • “Log Visualization in the Cloud” by Raffael Marty, Chief Logger, SecViz.org <– how come they don’t mention Loggly here?
  • “The Integration Lifecycle: Loving Long Logging Lifecycles” by Andrew Hay, CISSP, Senior Analyst, Enterprise Security Practice, The 451 Group <- high chance for an awesomeness boost from Andrew!
  • “Best Practice and Approaches for Log Management” by Ritesh Singhai, Senior Security Engineer, SecureWorks
  • “Delivering Value from SIEM” by Chris Burtenshaw, Information & Technology Risk Manager, Deloitte

Enjoy! And “see” you there on August 19th.

Possibly related posts:

Enhanced by Zemanta

Thursday, June 11, 2009

Fun Upcoming SIEM Roundtable

Just reblogging the announcement since I think it would be useful for my readers. These are fun panelists, BTW, not brainless drones (well, I don’t know Brendan personally, but I guess he is not one either :-)) so I suspect the discussion will be worthwhile.  And the questions are VERY good too: how does “Is  purchasing a SIEM solution a fiscally responsible act given the current state of the economy?” sound? :-)

============================================================

“SIEM Thought Leadership Roundtable" June 17, 2009 2:00PM ET

  • Mike Rothman - eIQ Networks

  • Mark Seward - LogLogic

  • Brendan Hannigan - Q1 Labs

  • Paul Stamp - RSA

Register Here

https://whitehatworldevents.webex.com/whitehatworldevents/onstage/g.php?t=a&d=667930266

Most IT security departments are swamped. On one hand they’re contending with a highly dynamic threat landscape and an ever-expanding technology portfolio that requires protection. At the same time they’re doing what they can to help fulfill a burgeoning list of audit and regulatory compliance requirements. And on their third hand … if only that were possible! Fortunately, Security Information and Event Management (SIEM) – which has long offered IT Security the prospect of re-gaining control – is possible. In this Thought Leadership Roundtable, we’ll get to the bottom of what makes SIEM different from other security management solutions as well as what level of investment is required to make it work. Questions our panel will address include:


• Is purchasing/implementing a SIEM solution a fiscally responsible act given the current state of the economy and IT security budgets?
• How much of the “compliance problem” does SIEM actually address?
• To what extent do SIEM solutions provide meaningful correlation and enable detection of threats that would otherwise go unnoticed?
• What does the future hold for SIEM, both in terms of functionality and its relationship to other security management solutions?

Thursday, October 09, 2008

Change!!!

No, this is not about a certain populist US politician :-) It is about a much graver subject indeed.

As of today, the only Chief Logging Evangelist in the world is no more. I have resigned from my position at LogLogic, effective October 9, 2008, which is today. Please don't contact me at the company email; use my personal email instead. My LinkedIn profile has been updated accordingly.

If you are curious, I still love logs. I really do. Logs are cute :-) You should love them too. And, it goes without saying, I will always remember that title, Chief Logging Evangelist, that I have created for myself. People did say that "Anton wakes up and thinks 'what else he can do today to make the world love logs?'" - it was pretty much like this. In fact, I think world does love logs a tiny bit more now and thus my mission of a logging evangelist has not been in vain.

I will be offline for the entire next week ("OMG, no blogging?" - "Nope, no blogging!") and you, my dear reader, will have to wait until October 20th to hear the news about ...

... where Anton is NOW!!!???

Yes, where is he? :-)

Talk to ya October 20th! The end always brings the new beginning ...

P.S. Please don't tell me that I have a penchant for dramatic. I know :-)

Technorati Tags:

Wednesday, October 01, 2008

My Lunch Presentation at SANS Network Security 2008

If you are at SANS Network Security 2008 in Vegas, come see me speak about "'Worst Practices' of Log Management." It is a fun presentation - and we (LogLogic) will feed you lunch. For those of you who cannot make it, I will release the slide deck here after I present it this last time...

Here is the announcement:
LogLogic Lunch and Learn Presentation
'Worst Practices' of Log Management
Speaker: Dr. Anton Chuvakin, GCIH, GCFA
Friday, October 3rd, 2008 * 12:30pm - 1:15 pm


BTW, I am arriving Thursday night, so if anybody wants to meet and "talk logs," please drop me an email.

UPDATE: presentation is posted here.

Possibly relates posts:

Monday, September 15, 2008

Fun Reading on Logs and Log Management - 2

I am amazed (no, AMAZED!) about how many people now write about logs; it is definitely not "the original logging evangelist" anymore :-) Here is a bunch of good log-related reading, useful for those struggling with logs (aka "everybody" :-))

  1. Our brilliant field engineer Dimitri McKay talks about the eternal topic of converting Windows event logs to syslog. Yes, Eric, we ALL know it is ugly, but that is the only way that actually works well across all systems ...
  2. More on Windows and syslog: "Syslog ... 20 Years Later." BTW, this is really not about syslog, but about Vista/2k8 finally getting an ability to natively centralize the event logs via event subscriptions ("It's only about twenty years behind schedule, if you're counting.")
  3. Two fun pieces on correlation: 1 and 2. What often kills "a log correlation project"? "Whoever had worked on it had not had much time available to learn the way to properly configure the software" (from this) and "correlation only really works when backed up by real data about what is the biggest problem in your environment, and how that problem manifests itself in the event logs." (from this) None of this is new, but a useful reminder nonetheless
  4. Fun LogLogic podcast is here. The topic of this high-level discussion (CEO) is related to operational use for logs. I did one with them too; on logs and virtualization (will be up soon)
  5. A couple of good posts on logging from Nemertes Research: "Sharpening Stones and Walking on Coals", "Search or Destroy"
  6. Reminder about a few useful Windows Vista and 2k8 events: 4802 (screensaver engaged) and 4803 (screensaver dismissed)
  7. One person is wondering about the usefulness of logging after "experiencing" Linux auditd logging (kernel audit): "Logs are like a warm blanket; verbose logging means you can know what's happening on your systems if you keep up with the logs. At the same time, logs become a burden very very easily, and they are easy to ignore." This post is a must read for us logging afficionados; producing too much log data is a sure way to make people hate you...
  8. This also follows the same theme: people doubting the god-like power of logs :-) "So for an administrator to not care about logs was a shock." But would I argue that "log management is NOT a pain?" Now, would I? :-)
  9. A classic about logging for application developers: "Building Secure Applications: Consistent Logging." I am noticing a lot more discussions about logging in a developer community, e.g. see this and this (the latter, BTW, contains a lot of info on "why log" for developers). Overall, "getting logging right" is important (and will get more important in the future) and people need something NOW and cannot wait for the standards. BTW, I am planning a mini-crusade on how to train application developers to include useful logging in their applications...
  10. Finally, the "Is SIEM dead?" theme is continued in this fun post "Life after SIEM. Situational Awareness is next." Indeed, context is key for logs. BTW, if somebody mentions that I have "vendor bias", I will kick your ass! :-)

Enjoy!

Possibly related posts:

Monday, August 04, 2008

Ideal Tool to Solve Real Problems ... of the Near Future? - II

I would like to continue the discussion I started in my previous post called "Ideal Tool to Solve Real Problems ... of the Near Future?" Specifically, upon outlining some problems with logging, I will now forecast what will happen with them in 18-24 months.

  • Which problems will be solved and forgotten?
  • Which ones will simply go away?
  • Which ones will persist and in fact increase?
  • Finally, which new ones might emerge?

First, let me bet my ass that "Not knowing what to log" problem will be licked in 18-24 months; at least as far as major regulations go, people will have a pretty good idea a) what  the auditors want them to log (and review!) b) what they need to log for solving their problems. Now, for esoteric log sources (and custom applications) might still present a challenge from that point of view, but for basic "staples" (firewall, network gear, major OS) the mystery will be over (again, see "Tell me EXACTLY what to log for PCI?"  for reference)

Next, the problem of "Log volume" will  definitely get worse, much worse.  One might think that 100,000 each second is a lot of log - but there WILL BE more at many companies! Big application log explosion is coming, fueled by the need to address logging in areas where such motivation was lacking before (basically, custom and vertical applications) as well as harness the power of "uncommon" logs for such tasks as fraud analysis or SOA monitoring. Keep in mind that even though in some areas logging is NOT a preferred way of monitoring and auditing activities (see this discussion on database logs here), application logging will still explode on us...

The problem of "Log diversity" (the fact that most logs all look different in format and meaning) will get worse before it will get better - and better it WILL (!!!) get since standards are being developed. We will see people struggling with all sorts bizarro log data in the coming years. Virtualization, web services and SOA, various ERP applications and even cloud services will increase the diversity of logging in the coming years.

Similar to the above, a problem of "Bad logs" (ones that are subjective, miss key information, require groping for a crystal ball to understand, turn log analysis into dark voodooistic experience or are useless in some other way) will also follow the pattern of the above log diversity problems - it will get worse before it gets better (via the CEE standard effort that now covers the OpenXDAS effort as well!) I noticed that people started asked me questions about "how to do application logging right?" and "what to tell application developers about logging?" which almost never happened in the past. BTW, watch my blog for some uber-fun info on that!

"Getting the logs"  has gotten much easier in recent years; agentless collectors like Project Lasso (which, BTW, just got updated) and grabbing  files remotely via secure protocols made application log collection easier (syslog-NG with TCP transfer and buffering also helped). Next, Windows 2008 will make it MUCH easier for the whole Windows kingdom due to their use of web services (thanks Eric!). However, in the future it might resurface as we try to collect logs from "weird" places, again, clouds come to mind as well as virtual environments (e.g. how do you get logs off a dormant VM?). What's the next frontier in this area? Log discovery - automatic finding and identifying log files on systems in order to analyze and retain them (Yo, my t-shirt-making colleagues... :-))

All this, however, pales in comparison with my favorite "uber-challenge", "Making sense of logs in  an automated fashion" - this baby is definitely not going away in 2-3 years. Much more research is needed to make that "log->conclusion" jump automatically without head-scratching, invoking ancient deities and cursing under ones's breath. Only then we can attempt to reliable handle "proactive logging" (i.e. analyzing various failure or compromise precursors in logs and then predicting the future based on them), another Holy Grail of logging domain.

Anything new will emerge? Yes, I think awareness of the "Logging Gap" problem will grow. "Logging gap" happens when you combine "a need to log" with utter "inability to do so."  For example, this will happen when people will know that they HAVE TO log, say, for compliance, but will have no way of doing it due to application or platform limitations. This will become one of the challenges and special "logging add-ons" will appear to close the logging gap and create additional logs where activity audit is desperately needed, but native logging is not helping to achieve it.

Also, I think people will finally wake up to "Log security" challenges - i.e. producing for use as evidence, compliance attestations, etc. Log security is not getting the attention it deserves, but I think this challenge will finally emerge in full force in the next 2-3 years. My next poll will address that :-)

Anything else I missed? Share away!

Related posts:

Monday, May 12, 2008

Log Management: Insight From Ancient Times (The 80s, That Is :-))

My boss has posted two of the very fun blurbs on log management to our blog; do check them out, especially if you are the fan of the 80s :-)
Fun blurbs from the above:

"In surveys, 70%+ of organizations confess their primary budget for log management still comes from compliance. However, this same group admits for years now that 70% of their use of log data is driven by operational needs such as fault detection and problem isolation."

"The requirement to collect 100% of all log messages of all log sources is even more important in operations than it is in security." (why?)

"Rather than replacing these systems with yet another console, most companies are going to look for the ability to integrate a new information source, log data in this case, into the existing fault management console. Web services likely will be the mechanism of choice."

Friday, February 29, 2008

OMG, Log Management TLR

OMG, OMG, OMG! :-) This will be an event of the century (... at least until the next one :-))

"Log Management Thought Leadership Roundtable Webcast" will features such log management / SIEM personalities as Hugh Njemanze, Anton Chuvakin, Chris Petersen and Mehlam Shakir, discussing what is and will be the coolest things in log management.

Date: March 5th
Time: 11AM PST / 2PM EST

BE THERE!

UPDATE: recording is posted; it was fun!!!

UPDATE2: fun comments from one of the attendees (David from Devil's Advocate Security blog) are here.

UPDATE3: I got a list of question from the organizers; many of them are fun and I will answer them on my blog later this week... stand by.

Wednesday, February 27, 2008

LogLogic User Forums Open

We got this brand-spanking-new "semi-official" LogLogic user forum here, and I have my own sub-forum called "Log Innovations." Feel free to drop by and participate.

As of now, I am reposting some of the most useful blog content there (such as the tips), but it will be used for other fun stuff on the future. Check it out.

Friday, February 15, 2008

One More Time on Log Management and SIEM

I did blog a lot to explain the connections and differences between SIEM and log management a few times (e.g. here, here, here, here), but here is a perfect high-level description from the interview with our new CEO: "One of the promising applications for log management is Security Information and Event Management (SIEM). [...] According to recent studies from ESG and the SANS Institute, security, risk and compliance issues comprise only 30% of all log management use cases."

Get it? SIEM is about "S" - security, while log management is about "L" - i.e. logs; logs for all uses inside and outside of security.

Friday, January 25, 2008

Webcast Version of My "Choosing Your Log Management Approach" Presentation

As I mentioned before, this presentation of mine called "Choosing Your Log Management Approach: Buy vs Build vs Outsource" will be turned into a webcast. It will first be aired on the following date:

January 29, 2008
2:00 p.m. EST/ 11:00 a.m. PST

Direct link to registration.

If you are dealing with logs (or planning to start!), it is a very worthwhile presentation to attend. And fun too!

Tuesday, January 15, 2008

I Should Really Not Touch This ....

... I really should not. But - darn it! - how can I miss a potential blog fight related to log management?

So, it seems like Raffy baited some poor folks from Prism with his post on "IT search" (what an abomination of a term!). But, seriously, "IT search" is a marketing term (nothing wrong with that, BTW!), so it will mean whatever the folks who coined feel at any given moment. I really hate it when folks try to argue objectively with a clear fluke.

I think this debate is mostly about two approaches to logs: collect and parse some logs (typical SIEM approach) vs collect and index all logs (like, ahem, "IT search").

You can see where this one is going, right? :-)

Yes, Virginia! You do need to do BOTH - and you know who does both? LogLogic!

Thursday, October 25, 2007

Some Fun LogLogic Stuff

Read this if you are into that type of stuff :-) This paper/interview covers some of the new things we built in the recent release. I also touch upon PCI, forensics and other uses for logs.

And, yes, it does have a few classic journalist distortions....

Monday, October 22, 2007

Friday, September 28, 2007

On LogLogic

A few people asked me how's LogLogic doing - this blog post from my boss pretty much says it all.

And - we are still hiring (even though we recently hired a whole bunch of really good people - as in "REALLY good" :-)). BTW, if you just like the company (and you should!), but not any particular position - please apply anyway!

Wednesday, September 19, 2007

I Wish, I Wish or "What's exciting about LogLogic?"

I wish (not really :-)) that this were true: "'The problem that LogLogic has is that it has no competitor so its market is ill-defined. There are point solutions that are appropriate departmental or divisional solutions but there is nothing really like LogLogic on an enterprise scale."

It does sound nice though (esp. this "Regardless of how you label it, LogLogic is clearly its own market leader.")

Fun read about us.

Friday, August 10, 2007

Build vs Buy for Log Management

My favorite SANS presentation that I gave a few times was "Choosing Your Approach to Log Management: Build, Buy, Outsource" (e.g. see here). This story that I just posted to LogBlog makes this build vs buy distinction painfully clear. Enjoy!

Wednesday, August 08, 2007

More On LASSO and Windows Logging

Here is a small blurb that I did for CNET on LASSO (our open-source agentless Windows-to-syslog collector) and Windows log collection. BTW, a new version of LASSO is out.

One thing to keep in mind is that you don't need LogLogic appliances to use LASSO: it can forward events to syslog-ng or other syslog destinations. However, if you do need more than a syslog server, LASSO works perfectly with the appliances as well.

Dr Anton Chuvakin