Feature details
Log analyzer engine
- Collectors
- Syslog UDP/TCP (Compatible with syslogd, rsyslog, syslog-ng, Lasso, Snare)
- Plain text file collector (Delimiter or fix width) over HTTP(S), FTP, SFTP
- Multi-line text collector
- Database connectivity, query a database, collect and analyze data from an SQL query (Supported JDBC datasources: PostgreSQL, MySQL, Oracle, MSSQL, SqlLite, Sybase, Derby, etc.)
- Native Solaris binary audit log collector
- SNMP trap collector
- Parser and analyzer modules
- Parse log data into fields
- Normalize log
- Index log
- Statistics, aggregation
- Create multi dimensional statistics real-time based on individual fields of log
- Events and Alerts
- Simple event generation
- Event generation based on multiple criteria (correlation)
- Baseline event generation (looking for anomailes)
- Store states and use them as a condition of events
- Alert and notify users or other systems when an event matching one or more specified criteria is generated
- Generate synthetic events and reuse them as input data
- LOGalyze SOAP API
- Connect remotely to SOAP API service
- Generate your own client from favorite SOAP toolkit (such as the toolkits for PERL or .NET) using the WSDL
- LOGalyze-CLI command line interface
Administrator interface
- General features
- Access via a customizable web based HTML user interface from any location at any time
- No client-side installation, saving time and simplify maintenance
- Multi-language user interface
- Log browser
- Grid view
- Show or hide columns, sort by any field of log
- Filter by columns
- Selection criteria designer
- Google-like-search
- Statistics viewer
- Multi-dimensional statistics
- Several graph types: line, bar, stacked column, grouped column, pie
- Data table
- Report generator
- Automatically generated reports
- Predefined Compliance reports
- Output formats: E-mail, HTML online, PDF, CSV, XLS
- Admin functions
- User and Role management
- Source log device management
- Customizable user interface
- Internal audit log
Log definitions
- Windows 2003 System, Security, Application event logs
- Windows 2008 event logs
- Linux standard events
- OS Audit Subsystem logs (Linux Audit Subsystem, AIX audit log, Solaris audit log)
- Network devices (Cisco, Juniper, SonicWall, etc.)
- Oracle audit trail
- System software logs (Apache, Postfix, Sendmail, Squid, etc.)
- Ability to parse custom business application logs
Next step: