The need for effective event
management
Challenges, strategies and solutions to effective event
management
GFI EventsManager is based on the simple fact that event log management is an indispensable tool in a corporate environment; a concept that due to its simplicity, system administrators often tend to overlook. Logs and their management are however one of the most important aspects in computer systems management. This white paper shows where GFI EventsManager fits in this picture and how it is an invaluable asset in the corporate toolbox.
WWW.GFI.COM The need for effective event management . 2
Introduction Underrated, undervalued and underutilized; events management is most often rated as a tedious and ungrateful task. System administrators shy away from event logs and the events contained within, citing lack of time and clear definitions to the events produced as the principle detractors to the events management process. Events however constitute an invaluable source of information that can be utilized in a number of business processes such as fact finding and decision making. Various laws also mandate that logs have to be maintained and reviewed. This paper examines various corporate needs and provides information on how GFI EventsManager can help corporations achieve important goals.
Introduction....................................................................................................................................2 Events management and GFI EventsManager.............................................................................2 Legal compliance...........................................................................................................................5 Information system security...........................................................................................................6 System health monitoring..............................................................................................................7 Forensic investigations..................................................................................................................8 GFI EventsManager ROI and benefits ..........................................................................................9 Conclusion.....................................................................................................................................9 About GFI ....................................................................................................................................10
Events management and GFI EventsManager
What are events? Events are records generated and stored in specific locations by processes within a computer system. Events are triggered either by a user or by an automatic/background process. Examples of the events logged abound:
. The installation of new software generates a wide range of events (in Windows Event Logs) detailing the installation procedure and the file details. . Web servers log huge volumes of events (in W3C event logs) related to the users that access services offered on them. . Firewalls and network routers automatically log events (Syslogs) related to allowed, denied and unauthorized access. Events logged are automatically stored in text files such as W3C logs (typically used in web servers) or binary files such as Windows Event Logs. Alternatively these can be transmitted on the network via TCP/IP for storage (ex. Syslogs used in Unix/Linux machines) to a log server. The log server then stores the received event logs in either a file or a database. Events
WWW.GFI.COM The need for effective event management . 3
management is the management, analysis and reporting process involved in the management of computer and user generated events data and the logs within which the generated events are stored.
The problems with events management The aura of discontent that surrounds events management derives from the fact that operating system and equipment manufacturers usually supply event analysis tools with only the most basic of features.
In addition events data typically is:
. Voluminous - Hundreds of thousands of events are generated daily on a typical mediu... [download for more]