"Nitro's ability to meet feature demands, coupled with its super fast NitroEDB data management engine on the back end put it in a unique position among SIEM vendors"
— Paul Roberts, Analyst, the 451 Group
 

Nitro on linked in Foolow us on twitter NitroSecurity's YouTube channel

 
 

Security Information & Event Management (SIEM)

Content-Aware SIEM

NitroView Enterprise Security Management, content aware SIEM
How to Buy
Contact Us to request a demo, or
call us at 888-LOG-SIEM

Features at a Glance
Full collection, correlation and reporting of:
  • Security alerts and events
  • Logs from devices, servers, and applications
  • Network flow information
  • Database activity
  • Application content

Ultra-fast architecture delivers performance and scalability
  • Collect data at 100,000 eps without compression
  • Collect data at 1,000,000+ eps with compression
  • Query collected information in seconds, produce full reports in minutes
  • Calculate baselines and trends in real-time
  • Instantly pivot or drill into data
  • Store years of data and access, analyze and report on it all

The only Content-Aware SIEM
  • Full visibility into application use and data access
  • Correlate application contents against other observed network activity and logs for maximum threat detection
  • Track user activity across applications and systems
  • Monitor and enforce business policies

Built-in support for all major compliance mandates:
  • HIPAA
  • HITRUST
  • NERC-CIP
  • PCI
  • SOX


Fully integrated with all NitroView products

Fully support for most third party network and security devices, including switches/routers, firewalls, IDS/IPS, anti-virus, application whitelisting, operating systems, privacy solutions, and even mainframes.

Easy to use, distributed appliance-based architecture

More Information
NitroSecurity Solution Brochure
Awards
Testimonials
ESM Product Specs

NitroView ESM is different from most information and event managers, using a patented high-speed data management architecture that enables it to effectively combine many security functions into a common user interface. This allows NitroView to extend beyond simple log and event collection, and support the direct monitoring of databases and applications, including full application decode for content monitoring.

NitroView is therefore able to collect, correlate and analyze more relevant security data than any other solution — including:

  • Device logs, including logs from servers, hosts, applications and databases
  • Event data, including alerts from firewalls, IDS/IPS devices, and other security devices
  • Network flows, including network communication details such as source & destination IP, duration, and byte counts
  • Application content, including the content of email messages, appropriate message headers, document content, and the contents of compressed documents or document archives
  • Protocols, including the detection of malformed protocols and protocol anomalies

All supported information is correlated and analyzed together for maximum visibility into your infrastructure. while reducing the total cost and complexity of overall Information Security functions.

Ultimately, it's all about the data. Unrestricted data collection provides maximum visibility into your infrastructure for better security, and provides greater detail and depth to audit reports for total compliance. NitroView integrates multiple solutions into a single, powerful system. The result is a solution that is greater than the sum of its parts.

Why is Content-Aware Security Information & Event Management Important?

Security Information and Event Management, or SIEM, promises to fill several primary roles:

  • Log Collection — to consolidate all relevant security information together for storage and analysis.
  • Incident Detection — which uses collected logs and events to discover threats, typically through correlation.
  • Information Storage — collected logs need to be stored, for compliance purposes as well as forensics.
  • Reporting — often focused on compliance, the SIEM must be able to provide access to stored information in the form of reports.
  • Incident Response — which provides detail and context required to investigate detected threats, stop them, and limit the chance of recurrence.

However, most first- and second- generation SIEMs fail to fulfill this promise. Why? Because effective security needs to look beyond the analysis of log files. Legacy SIEMs lack the performance and scalability to look deeper: network flow information, database activity, protocol activity, and application content — despite their importance to security and compliance — can not be supported by these older SIEMs.

content aware security information management SIEM
NitroSecurity NitroSecurity NitroSecurity NitroSecurity NitroSecurity NitroSecurity
NitroView console NitroSecurity
nitroview device support NitroView System shelf with device tree and common device tools NitroSecurity
event correlation for threat detection Event correlation detail NItroView integrated event and flow analysis NitroSecurity
nitroview security event detail for packet data and session detail event distributino voer time with trend analysis overlay NitroSecurity
NitroSecurity NitroSecurity
*This represents one of many pre-built dashboards within NitroView. Click areas of the image above for more detail. [more screenshots]



While legacy SIEM solutions support collection, correlation, storage, and reporting, NitroView ESM goes further. NitroView provides visibility beyond logs, to monitor and protect your data. In addition, NitroView provides real-time incident response functions. This is possible because NitroView ESM has the performance required to analyze and report on billions of events, logs or flows in seconds — allowing you to quickly assess large amounts of data over long periods of time, and get the results almost instantaneously.

  • Broader Correlation — finding patterns within collected data, log details, network & database activity, and even application content — for better detection of attacks, data loss, and fraud.
  • Faster Notification — to alert Information Security staff of threats and anomalies.
  • Greater Detail — maintaing more granular detail about events, from virtually any log source, but also from event sources, host agents, network flows, databases and applications — for better and more accurate reporting.
  • Greater Scalability — supporting the collection of millions of events per second from distributed sources, to ensure that nothing is missed.
  • Long-term Accessibility — makes more of your collected data immediately available for analysis — years worth.
  • Real-time Access to Security Information — for real-time analysis and rapid incident response — making NitroView a valuable operational system, and not just a reporting tool.
  • Better Context — providing identity, location, vulnerability, and other relevant information to every other piece of information.

The Value of Integration

Compliance regulations require that you have equipment in place to prevent intrusions, and to directly protect sensitive data, such as credit card numbers or personal identification information. They also require that you collect logs from through your enterprise, review them daily, and store them in a secure fashion so that they can be used for audit purposes. This translates to the need for database monitoring and intrusion prevention, as well as for log collection and analysis. This requires the installation and operation of separate facilities to perform these highly related tasks.

By providing a common solution, with a single interface to all of these functions, the complexity and cost of your daily security operations is dramatically reduced. Protection is increased, and compliance is met.

Further Reading

  1. SIEM Requirements and Considerations
  2. Cost Efficiency through Integration

Specifications 

NitroView Enterprise Security Manager Specifications

Select a Model for Specifications [Note: for US Army APL approved models, please visit our government site]

Model           Description                         Events/sec     Report   
speed*    
HDD**    
NS-ELM-XXXX NitroView Enterprise Log Manager (ELM) Integrated Log Management for NitroView ESM & NitroView Receiver
 NS-ESM-X5 NitroView ESM X5 "High Speed" Enterprise Security Manager provides Log Analysis, SIEM, and Network Analysis functions for large enterprise networks. 7TB local storage plus 500GB of in-memory storage for etremely high performance. One 3U appliance, plus one 2U Appliance. 40 Million 1 Billion events/sec 7TB +
500GB RAM
 NS-ESM-5750-R NitroView ESM 5000 Enterprise Security Manager provides Log Analysis, SIEM, and Network Analysis functions for medium to large enterprise networks. 7TB local storage. 3U Appliance. 4 Million 100 Million events/sec 7 TB
 NS-ESM-5510-R NitroView ESM 5000 Enterprise Security Manager provides Log Analysis, SIEM, and Network Analysis functions. 3.75TB local storage, 3U appliance 3 Million 50 Million events/sec 3.75 TB
 NS-ESM-5205-R NitroView ESM 5000 Enterprise Security Manager provides Log Analysis, SIEM and Network Analysis functions. 2.5TB local storage. 3U appliance. 2 Million 25 Million events/sec 2.5 TB
 NS-ESMRCV-5205-R NitroView ESM 5000 Enterprise Security Manager provides Log Analysis, SIEM and Network Analysis functions. Includes integrated NitroView Receiver for collection of third party feeds. 2.5 TB local storage. 3U appliance. Rated for 5,000 events per second and manages up to (5) NitroSecurity devices (IPS, DAM, or APM). 5,000 25 Million events/sec 2.5 TB
 NS-ESMRCV-4245-R NitroView ESM 4000 Enterprise Security Manager provides Log Analysis, SIEM and Network Analysis functions. Includes integrated NitroView Receiver for collection of third party feeds. 1.5 TB local storage. 1U appliance. Rated for 1,000 events per second and manages up to (3) NitroSecurity devices (IPS, DAM, or APM). 1,000 25 Million events/sec 1.5 TB
 NS-NRC-4245 NitroView Receiver, collects 3rd party logs, events and flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 18,000 events per second. 18,000 - 1 TB
 NS-NRC-2250 NitroView Receiver, collects 3rd party logs, events and flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 15,000 events per second. 15,000 - 1 TB
 NS-NRC-2230 NitroView Receiver, collects 3rd party logs, events and flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 10,000 events per second. 10,000 - 1 TB
 NS-NRC-1225 NitroView Receiver, collects 3rd party logs, events and flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 5,000 events per second. 5,000 - 500GB
 NS-ESS-5205 NitroView ESM 5000 Enterprise Security Server provides management for up to 10 NitroSecurity devices (IPS, DAM, or APM). Does not support 3rd party feeds. Redundant power, 2.5TB local storage. 3U appliance. 150,000 (NitroSecurity devices only) 25 Million events/sec 2.5 TB
 NS-ESS-2230-R NitroView ESM 2000 Enterprise Security Server provides management for up to 10 NitroSecurity devices (IPS, DAM, or APM). Does not support 3rd party feeds. 500GB local storage. 1U appliance. 150,000 (NitroSecurity devices only) 15 Million 500GB

* Typical SIEM reports (queries) will complete in a few seconds, even on very large event stores.

** NitroView ESM 5000 models utilize a raid 10 drive configuration, as well as redundant, dedicated drives for OS storage. The number listed above represents the usable capacity for event, log and flow storage.

*** The maximum number of supported devices per ESM is determined by the receiver model(s) used for collection.

Click to see a current list of supported data sources


Related Products

NitroView Database Monitor Specifications

Select a Model for Specifications

Model                  Description      Appliance      Supported DBs      Events/Sec     
NS-DBM-4245-R NitroView DBM 4000, Database Monitor Pack. 1U Appliance good DB2, Oracle, MS SQL, MySQL, SyBase 15,000
NS-DBM-2250-R NitroView DBM 2000, Database Monitor Pack. 1U Appliance goodDB2, Oracle, MS SQL, MySQL, SyBase 10,000
NS-DBM-2230-R NitroView DBM 2000, Database Monitor Pack. 1U Appliance goodDB2, Oracle, MS SQL, MySQL, SyBase 5,000

NitroView Enterprise Log Manager Specifications

Select a Model for Specifications

model              Description      Logs / Sec     
NS-ESMLM-5205-R NitroView ESM / ELM 5000 Enterprise Security Manager provides SIEM , Compliant Enterprise Log Management, and Network Analysis functions. Includes integrated NitroView Receiver for collection of third party feeds. 2.5 TB local storage. 3U appliance. 2,500
NS-ESMLM-5510-R NitroView ESM / ELM 5000 Enterprise Security Manager provides SIEM , Compliant Enterprise Log Management, and Network Analysis functions. Includes integrated NitroView Receiver for collection of third party feeds. 3.75 TB local storage. 3U appliance. 5,000
NS-ELM-5510-R NitroView ELM 5000 Enterprise Log Manager provides Compliant Log Management functions. 3.75 TB local storage. 3U appliance. 35,000
NS-ELM-5205-R NitroView ELM 5000 Enterprise Log Manager provides Compliant Log Management functions. 2.5 TB local storage. 3U appliance. 20,000
NS-ELM-4245-R NitroView ELM 4000 Enterprise Log Manager provides Compliant Log Management functions. Supports network / SAN storage options. No local storage. 1U appliance. 40,000
NS-ELM-5750-R NitroView ELM 5000 Enterprise Log Manager provides Compliant Log Management functions. 7 TB local storage. 3U appliance. 50,000
NS-NRCLM-4245-R NitroView ELM Receiver provides compliant Log Management and collects flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 10,000 events per second. 10,000
NS-NRCLM-2250-R NitroView ELM Receiver provides compliant Log Management and collects flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 8,000 events per second. 8,000
NS-NRCLM-2230-R NitroView ELM Receiver provides compliant Log Management and collects flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 5,000 events per second. 5,000
NS-LC-2250-R NitroView LogCaster 2000, 1U appliance. Includes (500) LogCaster Agent Licenses. Rated for 10,000 events per second. 10,000
NS-LC-2230-R NitroView LogCaster 2000, 1U appliance. Includes (250) LogCaster Agent Licenses. Rated for 5,000 events per second. 5,000
NS-LC-AGT-200 NitroView LogCaster Large Syslog Device Agent License for quantity 200 devices. Includes console software; supports *NIX Server, Firewall, IPS, etc... -
NS-LC-AGT-100 NitroView LogCaster Large Syslog Device Agent License for quantity 100 devices. Includes console software; supports *NIX Server, Firewall, IPS, etc... -
NS-LC-AGT-50 NitroView LogCaster Large Syslog Device Agent License for quantity 50 devices. Includes console software; supports *NIX Server, Firewall, IPS, etc... -
NS-LC-AGT-25 NitroView LogCaster Large Syslog Device Agent License for quantity 25 devices. Includes console software; supports *NIX Server, Firewall, IPS, etc... -

NitroGuard IPS Specifications

Select a Model for Specifications [Note: for US Army APL approved models, please visit our government site]

Model                     Description      Throughput      Copper
Ports     
Fiber
Ports     
NS-IPS-5450-R NitroGuard IPS 5000, 3U IPS appliance supporting approximately 4 to 5Gbps & 1.2m connections. Includes redundant power and a bypass NIC. 4-6 Gbps 12x1Gbps 4x10Gbps
NS-IPS-4245-R NitroGuard IPS4000, 1U IPS appliance supporting approximately 2Gbps & 1.5m connections. Includes redundant power and a bypass NIC. 2 Gbps 2, 4, 8 2, 4
NS-IPS-2250-R NitroGuard IPS 2000, 1U IPS appliance supporting approximately 750Mbps & 1.2m connections. Includes redundant power and a bypass NIC. 750 Mbps 2, 4, 8 2, 4
NS-IPS-2230-R NitroGuard IPS 2000, 1U IPS appliance supporting approximately 500Mbps & 1.2m connections. Includes redundant power and a bypass NIC. 500 Mbps 2, 4, 8 2, 4
NS-IPS-1225 NitroGuard IPS 1000, 1U IPS appliance supporting approximately 250Mbps & 1.2m connections. Includes single power and a bypass NIC. 250 Mbps 2, 4 2, 4
NS-IPS-1160 NitroGuard IPS 1000, 1U IPS appliance supporting approximately 150Mbps & 1.2m connections. Includes single power and bypass NIC. 150 Mbps 2 N/A
NS-IPS-110 NitroGuard IPS 100, Set-Top IPS appliance supporting approximately 50Mbps & 1.2m connections. Includes single power and a 2 port 10/100/1000 Base-TX copper NIC (no bypass). 50 Mbps 2 N/A





These icons link to social bookmarking sites to help share this content.
  • share this page:
  • bodytext
  • del.icio.us
  • Reddit
  • Slashdot
  • Technorati
  • Propeller
  • TwitThis
 

Search NitroSecurity.com