Security Analytics & Incident Detection
Centralized log collection from all sources
Log Intelligence
- Elasticsearch-based platform-based log analysis: Centralized collection and indexing of log and event data on a scalable Elastic platform for fast searches and powerful analyses.
- Rule-based event detection: Use of predefined and customizable detection rules to identify security-relevant events and suspicious activities.
- Event filtering: Rule-based filtering and prioritization of events to reduce irrelevant log data and focus on security-critical activities.
- Event correlation: Analysis and linking of events from different sources to detect complex relationships and anomalies.
- SIEM-optimized data: Pre-processing and filtering of log data so that only relevant security events are forwarded to a SIEM system.
- SIEM integration: Support for transferring normalized and enriched log data to existing SIEM platforms for advanced security analysis.
Log Collection & Processing
- Multi-source collection: Collection of log and event data from various sources such as servers, applications, network devices, cloud services, and security solutions via standardized interfaces.
- Agent-based and agentless data collection: Support for both agent-based log collection on hosts and agentless collection via Syslog, APIs, or network protocols.
- Standardized data normalization: Transformation of different log formats into a uniform data model for simplified analysis and correlation of events.
- Parsing and field extraction: Automatic processing of unstructured log data through parsing and extraction of relevant fields for structured analysis.
- Tagging and metadata enrichment: Supplementing log data with additional contextual information such as host, application, environment, or business context
- Timestamp correlation: Time synchronization and normalization across different systems for accurate event correlation.
- Data routing and indexing: Automatic forwarding of log data to appropriate indices or data structures for efficient storage and subsequent analysis.
Dashboards & Insights
- Visualization of events and log data: Display and analysis of centralized events and log data from servers, applications, network devices, and cloud services in real-time dashboards.
- Index-based search & analysis: Fast searching of large data volumes through powerful indexing and structured queries across all data sources.
- Correlation of logs, metrics, and events: Linking log data with infrastructure metrics and events for a more precise analysis of system states and dependencies.
- Time series and trend analysis: Analysis of historical data via time-series visualizations to identify patterns, load peaks, and changes in system behavior.
- Custom Dashboards: Creation of customizable dashboards with charts, heatmaps, and time-series views for detailed analysis of complex system data.
- Root cause analysis: Use of correlated event and log data for rapid identification of causes for performance issues, incidents, or security events.
For MSPs and MSSPs
- Distributed, multi-tenant architecture: Ideal for MSPs and large enterprises, with highly scalable and flexible deployment options.
- Role-based access control (RBAC): Granular access control for different user groups to ensure secure usage.
- Central Log Data Aggregator (iDN): Aggregation and analysis of logs securely uploaded by log collectors.
- Cluster-capable data nodes: Ability to form clusters for high availability and load balancing across multiple data nodes.
More in the i-Vertix Academy: Practical Knowledge, Technical Expertise and Best Practices
i-Vertix Academy: Dashboard Creation
i-Vertix Academy: Network Traffic Monitoring
i-Vertix Academy: Log Management
Don’t Miss What’s Next
Always stay one step ahead!
News, webinars, events, and concrete approaches for your service business – straight to your inbox.
Subscribe to our newsletter
Made in Europe