Follow Us

We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message



Part of a Group Review

ArcSight Logger review

Article comments

The initial logon takes you to a role-customisable dashboard, which at first focuses on the monitoring the system's performance, including CPU utilisation and event logging metrics. Most admins will spend much of their time within the Analyse tab, where search queries and alerts can be defined.

Search queries can be composed of keyword searches (for raw text searches across structured and unstructured data), as well as Boolean logic, and complex searches can be built using the Search Builder.

Directly typing in search queries is the fastest method for experienced admins, but the large number of expression choices can be intimidating to new users. Beyond understanding Boolean logic, advanced queries require an understanding of Logger's schema and the data it is collecting. Here's an example of a complex query: 

failed AND name="*[Bad Logon]*" AND categoryBehavior CONTAINS Stop NOT ("192.168.4*" OR REGEX=":\d31")

Luckily, the Search Builder graphically presents the various structured data fields available and lets the user point and click their way into complex queries. Search queries can be saved and even analysed before running to find any weaknesses.

No matter how you construct the query filter, the query itself is very fast. Most queries, even across tens of millions of events, only took seconds. Each query result includes how long it took the query to execute and how many events per second it queried to reach those findings. Queries can be executed across multiple Loggers at once. Results can be saved and exported, and the query can be turned into an alert. One note of caution: ArcSight has artificially limited Logger to five active alerts at once. More flexible alerting can be enabled in ArcSight's other products.

Reporting is another strong feature. Logger comes with many built-in reports; my favorite was the SANS Top Five report set and the ability to create customised reports. Logger has the most design and editing options for reports of any product in this review. Reports can be ad hoc, run on a predetermined schedule, converted into multiple formats (including HTML, PDF, and Microsoft Excel), or added to the dashboard.

There are four main types of Logger users: System Admins, Logger Operators, event log Searchers, and Reporters, who can only manipulate the reporting options. Each role can be configured with different levels of access and permissions. Other minor features, such as query granularity and storage rules, are continued evidence of Logger's maturity. Nearly every feature allows customisation, scheduling, export, and performance optimisation. Most data streams are encrypted by default, and Logger supports FIPS 140-2 encryption, certificates, and one-time passwords for remote technical support.


More from Techworld

More relevant IT news


Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Choose – and Choose Wisely – the Right MSP for Your SMB

End users need a technology partner that provides transparency, enables productivity, delivers...

Download Whitepaper

10 Effective Habits of Indispensable IT Departments

It’s no secret that responsibilities are growing while budgets continue to shrink. Download this...

Download Whitepaper

Gartner Magic Quadrant for Enterprise Information Archiving

Enterprise information archiving is contributing to organisational needs for e-discovery and...

Download Whitepaper

Advancing the state of virtualised backups

Dell Software’s vRanger is a veteran of the virtualisation specific backup market. It was the...

Download Whitepaper

Techworld UK - Technology - Business

Innovation, productivity, agility and profit

Watch this on demand webinar which explores IT innovation, managed print services and business agility.

Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

From Wow to How : Making mobile and cloud work for you

On demand Biztech Briefing - Learn how to effectively deliver mobile work styles and cloud services together.

Watch now...

Site Map

* *