Network World
Thursday, January 8, 2009
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Community: Security

Navigation

None of the solutions offered an agentless approach?

You noted in the article that many customers prefer not to install agents on DCs - were none of the solutions under test capable of collecting events from Windows devices (or others) without using agents, or was that a choice the review team made? In the interests of disclosure, I work for RSA and the envision (formerly Network Intelligence) solution does have an agentless collection feature for Windows that appeals to many customers.

Click to read the article this is in response to.

RSA declined to participate

0

So we can not verify these claims based on testing.

Christine Burns
Executive Editor, Testing
Network World

Many of the products we

0

Many of the products we tested had push/pull methods of gathering data and approaches varied heavily on what the data source was. (e.g. a Cisco firewall vs. a vulnerability scanner) I'm familiar with the approach of logging in remotely and "scraping" logs from Windows hosts and/or domain controllers, yes. Of course this presents other challenges such as making sure the SIEM platform has full connectivity to all of the Windows system in question (not always easy in a segmented environment), and forcing you to keep login credentials in your SIEM platform. (Although admittedly less risky if you restrict the "scraping" account's access rights...) It's also a pull model, which has some issues, too, but I digress...

Regardless, had RSA not chickened out of the review it would have been nice to have checked out that product's approach. :)

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <i> <b> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <blockquote> <br /> <br> <p>
  • Lines and paragraphs break automatically.
  • You can use BBCode tags in the text.
  • Web page addresses and e-mail addresses turn into links automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

Advertisement: