« Logs & The Law | Main | Log Data Management: A Smarter Approach to Managing Risk »
The SANS Institute recently defined a new metric for Log Intelligence performance: Real-Time Report Response Time (RRT). For too long, Log Intelligence performance was only measured in “Messages per Second (MPS)”. MPS capacity is useful when figuring out how many logging servers to buy, but doesn’t tell you about the daily user experience. (You can register to download a copy of the research into LogLogic's LS 2000 appliance)
Most real world log analysis is ad-hoc: a random combination of time frame, log sources and search criteria. With homegrown syslog servers, Report Response Times can be hours. Commercial solutions range the gamut: from one minute to many hours – even days. It pays to test before buying, because faster Response Times translate into big dollar savings.
For instance - an auditor walks in and asks about failed logins on your finance servers, then sees something unusual and asks follow-up questions. If each question takes eight hours to answer, an audit easily costs a million dollars in people-time alone! You fail your audit because you aren’t able to satisfy reporting requirements within regulated or defined timeframes.
Or - an alert indicates a security breach or performance problem. Resulting downtime costs a million dollars per hour. If faster Report Response Time helps to resolve the problem in one hour instead of eight you just saved seven million dollars! And that’s not calculating the costs you saved in terms of damage to reputation, brand and your customers’ business.
Messages per second matter but not nearly as much as response time. Some vendors will take an even more extreme approach to tuning messages per second, waiting to parse logs until reports are needed to be run. In this scenario, often with weeks of data collected, response times slow to hours. Remediation or forensics could take days or weeks. This is why LogLogic’s Real-Time Report Response Times never exceeds fifty seconds and in most instances can be measured in single digits.
LogLogic appliances pre-process log data at the time of log collection without sacrificing an inch of MPS. For large environments, multiple LX appliances crunch parts of Real-Time Reports in parallel, keeping Response Times independent of the amount of data analyzed. This is what results in ‘Google-like’ search speeds on terabytes of data.
The solution is simple when you are clear on the outcome that matters most to users.
Posted December 19, 2005 in Log Management & Intelligence | Permalink
TrackBack URL for this entry:
http://www.loglogic.com/mt/mt-tb.cgi/24
| Sun | Mon | Tue | Wed | Thu | Fri | Sat |
|---|---|---|---|---|---|---|
| 1 | 2 | 3 | 4 | 5 | 6 | 7 |
| 8 | 9 | 10 | 11 | 12 | 13 | 14 |
| 15 | 16 | 17 | 18 | 19 | 20 | 21 |
| 22 | 23 | 24 | 25 | 26 | 27 | 28 |
| 29 | 30 |