Centralized event and log data collection
Effectiveness of real-time centralized event and log data collection
Cat avg: 9
Effectiveness of real-time centralized event and log data collection
Cat avg: 9
Correlation of logs and events to pinpoint significant threats
Cat avg: 8.4
Ability to normalize event syntax so that logs can be compared and are machine-understandable
Cat avg: 8.5
Ability to tune system to maximize threat detection and minimize false positives
Cat avg: 7.7
Integration with access control tools like Active Directory and LDAP
Cat avg: 7.7
dashboards that can be customized to meet the needs of specific groups
Cat avg: 8
Ability to detect both endpoint intrusion and network ingress detection
Cat avg: 7.4
Security Information and Event Management is a category of security software that allows security analysts to look at a more comprehensive view of security logs and events than would be possible by looking at the log files of individual, point security tools
Effectiveness of real-time centralized event and log data collection
Category average: 9
Correlation of logs and events to pinpoint significant threats
Category average: 8.4
Ability to normalize event syntax so that logs can be compared and are machine-understandable
Category average: 8.5
Ability to tune system to maximize threat detection and minimize false positives
Category average: 7.7
Integration with access control tools like Active Directory and LDAP
Category average: 7.7
dashboards that can be customized to meet the needs of specific groups
Category average: 8
Ability to detect both endpoint intrusion and network ingress detection
Category average: 7.4
Effectiveness of real-time centralized event and log data collection
Correlation of logs and events to pinpoint significant threats
Ability to normalize event syntax so that logs can be compared and are machine-understandable
Ability to tune system to maximize threat detection and minimize false positives
Integration with access control tools like Active Directory and LDAP
dashboards that can be customized to meet the needs of specific groups
Ability to detect both endpoint intrusion and network ingress detection