LogBlog

« Protecting Against Data Theft | Main | Descending Into Log Policy Hell »

Lies, Damn Lies & Log Messages Per Second

As more SIEM vendors make their first forays into log management, price/performance claims are muddying reality - and more importantly miss what customers care about altogether.

First lets set the record straight, vendor to vendor. Whether it's 75,000 messages per second (MPS) or more, you're not talking leadership, you're talking entry point. We're proven by independent analysts and customers at sustained rates exceeding that so we'll leave it at that. What ultimately matters is not MPS but time-to-information. If you're working an incident, troubleshooting a datacenter or working an audit you care less about MPS and more about time to critical data, reports and insight. LogLogic is the only vendor to combine Agile Reporting (much broader than SIEM) with Google-like indexing and search. (Watch for more on this topic over the next day).

Second, price. SIEM's have a reputation for being expensive. Their proprietary logging appliances appear to be priced from the same playbook. In the case of the most recent, starting at $75,000 (and that excludes the proprietary SIEM you'll need to also purchase for reporting) you are looking at unvalidated performance at about 30% more than more feature-rich Log Management solutions.

And what do proprietary LMI solutions do - they lock you in to proprietary SIEM. Through our Open Log Services, we are able to open the log data - and intelligence, to be easily shared with other applications, including SIEM. And, our Services Oriented Architecture enables new applications to be easily developed and reused. LogLogic's Open Log Services have been developed based on the principles of SOA and conforms to all major standards (Java, SOAP, XML, PERL, PHP and .NET). We have the complete details here.

What newcomers to the log management and intelligence market really mean is more market validation. Spurious claims aside, they are recognizing what we saw four years ago - a distinct and growing customer requirement. But we also hope to hear more about openness and support for all customers in this vastly growing space and hopeful that we are not seeing another extension of SIEM that will promote yet another vendor lock-in strategy, a strategy to trap them into yet another high-priced solution. And a vision that goes beyond SIEM. The vision we see -solutions for IT performance, compliance and information asset protection - all architected for the Enterprise to an SOA - is very different to one rooted in a SIEM legacy.

Technorati : , , ,

Posted December 04, 2006 in Log Management & Intelligence , Security | Permalink


TrackBack

TrackBack URL for this entry:
http://www.loglogic.com/mt/mt-tb.cgi/111

Visit loglogic.com

I ♥ Logs

Subscribe to this blog’s feed RSS

November 2007
Sun Mon Tue Wed Thu Fri Sat
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30  
Categories
Archives
Blogroll
Blogroll
Compliance
Good Reading
LogLogic
LogLogic Partners
Sites We Watch