• LinkedIn
  • Twitter
  • Facebook
  • rss

Cisco MARS

Platform

Products

Solutions

Customers

Partners

Learn More

Support

Company

Overview Virtual Appliance SaaS
AccelOps APM AccelOps SIEM
Data Center Monitoring Virtualization and Cloud Management Business Service Management Compliance Automation Enterprise Search and Analytics
Why AccelOps? AccelOps vs. Competitors Customer Testimonials Limited Time Trade-in Offer Free Trial Download
Meet our Customers
AccelOps Partner Program Channel Partners Technology Partners Deal Registration Become a Partner
Analyst Coverage Document Library Videos & Demos Webinars & Podcasts FAQ Blog
Support Professional Services
About AccelOps Management Board of Directors In the News Press Releases Careers Contact Us
  • AccelOps APM
  • AccelOps SIEM
 

Overview

Details

Screenshots

Resources

AccelOps SIEM - Details

With an integrated and cross-correlated view into your network, devices, apps and user logs, AccelOps simplifies the collection of information that impacts your business.

With a powerful analytics engine, automated CMDB and event consolidation, smart anomaly detection, identity and location binding, and flexible data management, we redefine the next generation of SIEM.

Network Computing
Greg Shipley Reviews AccelOps:
Download the PDF file
10 Reasons to Migrate from Cisco MARS to AccelOps
Read the PDF
30 Day Free Trial
Get Started with a Live Demo, or a
30 Day Free Trial

Why AccelOps SIEM is Better

Single Solution for Real-Time and Historical Analysis

All of your data -- both real-time and historical -- is saved in the same optimized and scalable storage repository, allowing instant access to your real-time event and historical log data all with a single tool.

Compliance Automation

AccelOps ships with over 800 predefined reports including a comprehensive set of compliance reports covering PCI, HIPAA, and COBIT.

Advanced Rule Framework Addressing Sophisticated Threats and Violations

AccelOps supports simple thresholds advancing analytics to describe any scenario of interest. The rule language supports multiple sub-patterns (AND, OR, FOLLOWED_BY,..), broad operators (equals, greater than, contains, between,...), nested rules, and rule exceptions.

Flexible Reporting with Custom Dashboards

Any of the supplied reports may be copied or modified, or new reports built from the ground up to meet your requirements. Event and log data can be analyzed through simple keyword searches or complex conditional statements, resulting in detailed reports and graphs which in turn may be further explored by drilling down on specific results.

Multi-Vendor Device Support

We discover all aspects of your IT infrastructure – networks, servers, storage, users, and applications, then monitor availability, performance, change, and security, enabling you to pinpoint the root cause of an incident in record time.

High Performance Event Processing

We use a patent-pending XML based event-parsing framework, providing device support flexibility without sacrificing event processing performance. Additionally, new devices and applications can be supported without a software upgrade.

Flexible Deployment Models (SaaS or Virtual Appliance)

Leverage your VMware investment with our Virtual Appliance (software on premise) model, or take advantage of our subscription-based SaaS (Software-as-a-Service) model.

Smart incident management

AccelOps employs advanced alert consolidation, auto-suppression rules, instant filtering, service impact analysis and state management to reduce notification noise and sharpen administrative focus on a select set of active incidents.

Business Service Prioritization

AccelOps provides a platform for quickly mapping IT infrastructure elements to business services, then analyzing the performance, availability and security issues of each business service. This enables better incident prioritization, faster problem diagnosis and greater uptime for the services that matter to your business

Dynamic Adobe Flex Web 2.0 GUI

Our user interface is built from the ground up with the Adobe Flex Web 2.0 RIA framework allowing for a more engaging desktop application experience, while still running within any browser, offering anytime, anywhere accessibility.

Integrated Monitoring with Multi-Tenancy and MSP support

AccelOps features the industry's first integrated security, availability and performance management solution designed from the ground up with multi-tenancy and MSP support. This allows for both customer and service provider views and cross-correlation of events across multiple organizations.

AccelOps SIEM FAQ MARS Blog Review
CRN Top 100
CRN Top 100

The Top 20 Cloud Software and App Vendors of 2011

"AccelOps forges into integrated data center and cloud services monitoring with software delivered as a virtual appliance or SaaS."   More...

CRN Tech Innovators
CRN Tech Innovators

CRN Xchange Tech Innovator Awards: Technologies with Channel Punch

"AccelOps, a developer of integrated data center and cloud service monitoring software won the Editor's Choice, runner up award", said Eddie Correia, Technical Editor, CRN Test Center.   More...

Frost & Sullivan
Frost & Sullivan

Frost & Sullivan 2011 Global New Product Innovation of the Year Award

Presented to the company that has demonstrated technological superiority, functional innovation and differentiation within their industry that results in increased customer value and market potential.   Download PDF of the Frost & Sullivan announcement...

Network World
Network World

Top 10 IT Management Technology
Start-ups To Watch in 2010

"Companies like AccelOps offer their management SaaS, which enables IT managers to reap the benefits of sophisticated management software without having to invest the time in installation and maintenance of the applications."   More...

SaaS Showcase Award
SaaS Showcase Award

Winner of the Best of SaaS Showplace Award

"The award recognizes SaaS companies that are producing tangible business benefits for specific user organizations. AccelOps allows organizations to better leverage virtualization technologies and cloud computing."   More...

Secure Computing Magazine
Secure Computing Magazine

Finalist in the Excellence Award Category as Best Rookie Startup of the Year

"AccelOps is recognized by Secure Computing Magazine in their SC Awards, Excellence Award category as Best Rookie Startup of the Year."   More...

Network Products Guide
Network Products Guide

AccelOps Named 2010 Hot Company Finalist by Network Products Guide

"Selected from a global industry analysis of information technology vendors, AccelOps advanced to the finalists stage based on the '4Ps' selection criteria – namely Products, People, Performance, and Potential."   More...

Computer Technology Review
Computer Technology Review

Integrated Monitoring That Cuts through Datacenter Complexity

"AccelOps provides a level of integration and resulting correlated data that would be difficult to obtain using other management tools," said Mark Brownstein of Computer Technology Review.   More...

CRN Test Center
CRN Test Center

CRN Test Center Recommended

"What we found [in AccelOps] was an extremely powerful, stable and comprehensive monitoring & management tool that would benefit nearly any organization... Among AccelOps' most useful capabilities is its ability to present a complete picture of what's happening in any compute scenario across all company boundaries... the CRN Test Center highly recommends AccelOps."   More...

Compliance

Log Matters

Event log management / security information event management (SIEM) is considered an IT best practice, and for regulated industries, an audit compliance requisite.

The challenge is how to consistently aggregate, decipher and normalize non-standard log formats; manage massive volumes of event log data for real-time and historic analysis; correlate and consolidate complex event log data to yield actionable intelligence; and maximize event log value to support IT service reliability.

Some equate log management to log aggregation, display, and storage – a simple approach that fails to address these complex challenges. Most SIEM products offer basic event consolidation, simple correlation rules, limited real-time analysis, poor reporting and investigation flexibility, and no identity or infrastructure context. Many still require special collectors, add-on modules, additional systems and significant expertise.

AccelOps' founders and core team developed one of the industry’s most successful security event management solutions. We are again changing the playing field with our all-in-one, scalable datacenter and IT service management solution. See how AccelOps leverages network performance, applications, change management, identity, location, virtualization, and other intelligence to take SIEM to the next level.

AccelOps SIEM 2.0 - Robust Log Management and Beyond

AccelOps delivers a robust, scalable log management solution offering:

  • Mainstream device support
  • Event source monitoring
  • Event log and network flow data consolidation
  • Comprehensive, extensible analytics
  • Network, virtualization, and application intelligence
  • Identity and location intelligence
  • Configuration and configuration change monitoring
  • In-depth database security, availability and anomalous activity monitoring
  • Powerful, layer 7 rules engine
  • Real-time and historical cross-correlation
  • Prioritized, valid security incidents with correlated and raw details
  • Dynamic dashboards, topology maps and notification
  • Real-time and long-term search with web-like query and iterative filtering
  • Directory service integrated and custom asset and user grouping
  • Compliance and standards-based reports
  • Optimized event repository
  • Event log data integrity secured by HMAC
  • Unlimited online data retention
  • As needed performance and coverage capacity
device tree

Collect, Parse, Correlate from anywhere

Supporting multi-vendor device sources and advanced parsing technology, AccelOps can collect, parse, correlate and store logs from virtually all IT infrastructure sources. The solution automatically interprets the device type and how to process the event logs as they are received.

  • Network activity logs from Firewalls, Routers, Switches, VPN Gateways, Wireless LAN, Web/Mail Security Gateways, and Network IPS
  • Network resource utilization and anomaly detection from network flow data
  • Server operating system activity logs from Windows, Unix, Linux and virtual machines
  • Network infrastructure application logs from domain controllers, authentication servers, DNS and DHCP servers, and vulnerability management servers
  • User application logs from web, application, and database servers

The parser intelligently categorizes the source of the log into different device groups such as Firewalls, Routers/ Switchers, Wireless LAN Controllers, Printers, etc. It also groups into various server categories such as Windows, Unix, VMWare, and storage devices.

device tree

Automatic Discovery

AccelOps automatically discovers your network infrastructure and its resources using intelligent scanning methods. It supports a smart scan method, which iteratively learns only about the live devices in your network. Since only live devices are traversed, it is much faster than other traditional methods of network discovery.

It also supports a range scan method where each machine in the range is first pinged and then an attempt is made to do full discovery using the given credentials. Once the capabilities of the devices are known, the performance metrics which can be fetched from those devices are automatically determined.

credentials

Multi-Faceted Data Collection

AccelOps supports virtually all agent-less and agent-based data collection methods to collect logs from a variety of devices and applications including:

  • SNMP
  • Syslog
  • Windows Management Instrumentation (WMI)
  • Microsoft RPC
  • Cisco SDEE
  • Checkpoint LEA
  • JDBC
  • VMWare VI-SDK
  • JMX
  • Telnet
  • SSH
  • NetFlow
  • HTTPS
  • IMAP
  • IMAP over SSL
  • POP3

Powerful Analytics for Real-time Correlation and Alerting

200 plus rules

AccelOps can detect network services and profile network traffic from network flows and firewall logs. An advanced analytics engine detects patterns in data over a rolling time window taking into account very complex patterns. This includes combined patterns of network, system, application and user activity. The built-in analytics engine can be easily extended using XML-based definitions.

AccelOps contains more than 200 built-in rule classes which cover scenarios such as:

  • Host scans, port scans, fixed-port host scans, denied scans and other traffic anomalies from firewall and netflow logs
  • Network device and server logon anomalies
  • Network access anomalies from VPN, domain controller and wireless logons
  • Web server and database access anomalies
  • Rogue workstations, PDAs, WLAN APs etc. from DHCP logs
  • Account lockouts, password scans and unusual failed logon patterns
  • Botnets, mail viruses, worms, DDOS and other day zero malware from DNS, DHCP, web proxy logs and flow traffic

The analytics engine patterns are comprehensive and allow for complete Boolean operators and nested sub-pattern rules:

  • Sub-patterns connected in the time dimension by operators such as AND, OR, FOLLOWED_BY, AND_NOT, NOT_FOLLOWED_BY
  • Each sub-pattern can apply condition operators such as =, !=, BETWEEN, IN, NOT IN, IS, IS NOT, etc
  • Each sub-pattern can filter and apply aggregation operators such as AVG, MAX, MIN, COUNT, and COUNT DISTINCT
  • The thresholds can be static or statistically derived from automatically profiled data

Customizable Dashboards

The built-in summary dashboards provide a consolidated overview of performance, availability, and security status for all devices and applications which belong to a specific functional group or business service.

Using a fast update mechanism and leveraging the Adobe Flex interface, AccelOps screens are refreshed quickly and automatically to provide quick insight into the current health of network devices, servers, applications, and services. Health is presented in three simple grades: normal, warning, and critical. You can conveniently drill down and obtain the details for each metric along with trends, to proactively manage issues and respond to problems or threats before they become critical. You can further tune the performance of health parameters according to the criticality of the device.

AccelOps also features fully customizable dashboards across availability, performance, change and security dimensions including TopN information on various metrics along with the system itself.

The solution contains more than 400 customizable widgets and can be drag-and-dropped into any dashboard. Each widget can be further customized to provide aggregate, trending, or tabular views. You can adjust the layout by easily selecting from several options and choose from charting displays such as time series trending, pie, column, or spark line charts

The fast auto-refresh mechanism allows the near real-time update of the dashboard data to provide a current view into infrastructure issues and threats as they occur. You can quickly obtain additional context within dashboard object health status by instantly running a query or drilling down into specific incidents.

Instant Drill down

Instant Drill Down

One-click, recursive drilldown can be performed on any column to make refining search criteria a breeze and to expedite root-cause analysis that is less error prone. The quick information will provide detailed information about IP address, MAC address or user. In addition to the inventory data, it shows the health summary of the server without leaving the context.

You can select to view multiple rows of interesting information within the same trend view using checkbox selections in order to help pinpoint anomalies in the network behavior in a matter of seconds.




Cisco MARS
  • Why AccelOps?
  • AccelOps vs. Competitors
  • Customer Testimonials
  • Limited Time Trade-in Offer
  • Free Trial Download
Platform
  • Overview
  • Virtual Appliance
  • SaaS
Products
  • AccelOps APM
  • AccelOps SIEM
Solutions
  • Data Center Monitoring
  • Virtualization & Cloud Management
  • Business Service Management
  • Compliance Automation
  • Enterprise Search and Analytics
Customers
  • Meet our Customers
Partners
  • AccelOps Partner Program
  • Channel Partners
  • Technology Partners
  • Deal Registration
  • Become a Partner
Learn More
  • Analyst Coverage
  • Document Library
  • Videos & Demos
  • Webinars & Podcasts
  • FAQ
  • Blog
Support
  • Support
  • Prof Services
Company
  • About AccelOps
  • Management
  • Board of Directors
  • In the News
  • Press Releases
  • Careers
  • Contact Us
Copyright © 2011 AccelOps, Inc. All rights reserved.
  • Terms of Use
  • Privacy