Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Tenable Blog

Subscribe

Full Log Aggregation, Storage and Search

Tenable has released version 3.2 of the Log Correlation Engine (LCE) which includes the ability to store, compress and search any log that is sent to it. This functionality is available to all current LCE customers as a point release upgrade. It also builds upon the existing log normalization, correlation, user tracking and anomaly detection that were already available in prior versions.

Click on the below image for a demonstration of the LCE performing full log searches from within the Security Center:

Full Log Search

High Speed Ad Hoc Searches

The LCE can be used to perform a search for any type of ASCII log. Searches can be made with Boolean logic and limited to specific date ranges. There are an infinite number of searches that can be performed, but some of the ones we’ve seen our customers use in early product testing include:

  • Searching DNS query records for destination sites that indicate malware or virus infections.
  • Seeing which network users visit sites such as Twitter, CNN or YouTube gathered from web proxy logs.
  • Tracking down known Ethernet (MAC) addresses in switch, DHCP and other types of logs.
  • Generically looking for errors, system crash and reboot messages.
  • Finding certain types of Windows event records that indicate system issues.

All search results are saved in a compressed format along with a checksum so that they can be used as forensic evidence. Previous searches can also be re-launched against the latest logs.

Distributed Architecture

The Security Center can manage multiple LCE instances. From a user’s point of view, searches occur across all LCEs that they have access to. If they wish to narrow their search down to just one instance, they can choose to do that.

Each LCE has very high performance for gathering, compressing and searching logs. Tenable has achieved 20:1 compression ratios with some of our evaluation customers. When multiple LCEs are used together, the distributed query is also much faster than performing a similar query against just one LCE. For example, querying three LCE instances with similar logging loads was more than two times faster than one LCE.

Each LCE can use a local disk store or a mounted file system from a remote NAS or SAN. The Security Center can show the disk space usage of each LCE and also predict and alert when it will run out of disk space. Since the LCE does not make use of any third party databases, expanding your logging infrastructure is as easy as procuring a new LCE license and setting up a new server for your logs to be sent to.

Fulfilling Compliance Requirements

Full log aggregation, storage and search are all requirements of many compliance regulations such as PCI and FISMA. Organizations that are already using the Security Center and Nessus to fulfill their vulnerability and configuration auditing requirements for these regulations, can now take advantage of LCE’s ability to manage and search logs.

Many organizations are also subject to mandatory breach disclosure laws. Having direct access to raw logs, correlated events, configurations and vulnerabilities can help incident responders make immediate and correct decisions during a breach. This can result in not only limiting an ongoing breach, but also minimizing the chance of over-reporting or under-reporting the extent of a system compromise.

Obtaining the Log Correlation Engine

Tenable has worked with many customers that have been able to deploy a Security Center, Nessus and Log Correlation Engine solution as a replacement to multiple existing products. The combination of features offered by this solution has often allowed customers the opportunity to replace an array of vulnerability scanning, log analysis, configuration auditing, patch auditing and correlation tools. Tenable customers have also saved time and energy training their staff in one product solution and minimized the number of servers and appliances required to operate their auditing and monitoring infrastructure.

Any Security Center customer can upgrade their solution to full log analysis and correlation with a Log Correlation Engine. Each LCE is available in two options. A smaller version can analyze up to 15 million normalized events and a larger version can track close to 1 billion normalized events. Both versions can make full use of the local disk drive or network storage for full log searching and aggregation. To learn more about Tenable’s log analysis and storage products, please contact us at [email protected] and also consider watching one of our log analysis demonstration videos.

Related Articles

Cybersecurity News You Can Use

Enter your email and never miss timely alerts and security guidance from the experts at Tenable.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose Your Subscription Option:

Buy Now

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose Your Subscription Option:

Buy Now

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose Your Subscription Option:

Buy Now

Try Tenable Web App Scanning

Enjoy full access to our latest web application scanning offering designed for modern applications as part of the Tenable One Exposure Management platform. Safely scan your entire online portfolio for vulnerabilities with a high degree of accuracy without heavy manual effort or disruption to critical web applications. Sign up now.

Your Tenable Web App Scanning trial also includes Tenable Vulnerability Management and Tenable Lumin.

Buy Tenable Web App Scanning

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

5 FQDNs

$3,578

Buy Now

Try Tenable Lumin

Visualize and explore your exposure management, track risk reduction over time and benchmark against your peers with Tenable Lumin.

Your Tenable Lumin trial also includes Tenable Vulnerability Management and Tenable Web App Scanning.

Buy Tenable Lumin

Contact a Sales Representative to see how Tenable Lumin can help you gain insight across your entire organization and manage cyber risk.

Try Tenable Nessus Professional Free

FREE FOR 7 DAYS

Tenable Nessus is the most comprehensive vulnerability scanner on the market today.

NEW - Tenable Nessus Expert
Now Available

Nessus Expert adds even more features, including external attack surface scanning, and the ability to add domains and scan cloud infrastructure. Click here to Try Nessus Expert.

Fill out the form below to continue with a Nessus Pro Trial.

Buy Tenable Nessus Professional

Tenable Nessus is the most comprehensive vulnerability scanner on the market today. Tenable Nessus Professional will help automate the vulnerability scanning process, save time in your compliance cycles and allow you to engage your IT team.

Buy a multi-year license and save. Add Advanced Support for access to phone, community and chat support 24 hours a day, 365 days a year.

Select Your License

Buy a multi-year license and save.

Add Support and Training

Try Tenable Nessus Expert Free

FREE FOR 7 DAYS

Built for the modern attack surface, Nessus Expert enables you to see more and protect your organization from vulnerabilities from IT to the cloud.

Already have Tenable Nessus Professional?
Upgrade to Nessus Expert free for 7 days.

Buy Tenable Nessus Expert

Built for the modern attack surface, Nessus Expert enables you to see more and protect your organization from vulnerabilities from IT to the cloud.

Select Your License

Buy a multi-year license and save more.

Add Support and Training