Security engines need to be able to log specific types of connections
and events. This information is used for troubleshooting and to detect intruders, recover from an
incident and provide evidence of an attack.
StoneGate provides detailed and easy-to-manage views to security
events. From the log entry you can, for example, open directly to the corresponding rule from the
security policy. The log browser also contains statistical figures of filtered log entries. Using
this view you can easily see the traffic peaks of your security system.
See
demo about how to use log time line.
Typically, multiple log servers are used in larger StoneGate installations. To the administrators, the log information from all of these is consolidated to a single log browser. This makes it faster to find relevant information when, for example, investigating an incident, regardless of which StoneGate security engine has created the information.
Log entries can be exported to XML, CSV or PDF format. Incident management teams often need to communicate the details to other groups or a forensics team.Log Query panel provides easy and efficient tools for accurately retrieving the data needed.
See demo
how to filter logs and use a statistics view.
Service Providers and large enterprises often need to give their customers or remote offices access to the logs of their security modules without actually granting them access to the Management Server. For example, a service provider may permit customers to view their own security logs as part of the service-level agreement while prohibiting access to other customers' logs.
StoneGate Monitoring Client enables live viewing of security logs. Data access rights can be defined separately for each customer or remote office. Users can access log data as they are generated rather than waiting for hourly, daily, or weekly reports.