<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Do you use any tool that does automated log reviews? in Governance, Risk, Compliance</title>
    <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Do-you-use-any-tool-that-does-automated-log-reviews/m-p/40638#M180</link>
    <description>&lt;P&gt;A SIEM is capable of log centralisation, normalisation and correlation of events.&amp;nbsp; You should be able to set-up rules to alert on single events or combinations of events of interest.&amp;nbsp; It tend to be best to work back from known indicators of attacks to source the relevant events, rather than capture all events and try to figure out what all that data might mean.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Nov 2020 14:48:32 GMT</pubDate>
    <dc:creator>Steve-Wilme</dc:creator>
    <dc:date>2020-11-09T14:48:32Z</dc:date>
    <item>
      <title>Do you use any tool that does automated log reviews?</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Do-you-use-any-tool-that-does-automated-log-reviews/m-p/40616#M179</link>
      <description>&lt;P&gt;I am trying to automate this laborious task.&amp;nbsp; Can share if you have any experience using such tools where&amp;nbsp; auditors has no issue with?&lt;/P&gt;</description>
      <pubDate>Sat, 07 Nov 2020 02:28:58 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Do-you-use-any-tool-that-does-automated-log-reviews/m-p/40616#M179</guid>
      <dc:creator>CY</dc:creator>
      <dc:date>2020-11-07T02:28:58Z</dc:date>
    </item>
    <item>
      <title>Re: Do you use any tool that does automated log reviews?</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Do-you-use-any-tool-that-does-automated-log-reviews/m-p/40638#M180</link>
      <description>&lt;P&gt;A SIEM is capable of log centralisation, normalisation and correlation of events.&amp;nbsp; You should be able to set-up rules to alert on single events or combinations of events of interest.&amp;nbsp; It tend to be best to work back from known indicators of attacks to source the relevant events, rather than capture all events and try to figure out what all that data might mean.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 14:48:32 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Do-you-use-any-tool-that-does-automated-log-reviews/m-p/40638#M180</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2020-11-09T14:48:32Z</dc:date>
    </item>
    <item>
      <title>Re: Do you use any tool that does automated log reviews?</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Do-you-use-any-tool-that-does-automated-log-reviews/m-p/40639#M181</link>
      <description>&lt;P&gt;Are these internal or external auditors?&amp;nbsp; The difference: If they are internal, you could sit with them while you are putting together the requirements for such a tool and have their blessings as you move down the path.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not sure about others but have found that building an alliance with the IA team has been beneficial and helps when dealing with external audit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For external auditors, you may wish to ask them what they are looking for.&amp;nbsp; SOmetimes it varies depending on the auditor assigned to your firm.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We had good luck with Splunk (but they were very expensive), another tool we used was AlienVault.&amp;nbsp; Both satisfied the audit requirements.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;d&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS: this is&lt;STRONG&gt; NOT&lt;/STRONG&gt; an endorsement for either tool, just that we used them.&amp;nbsp; Both had issues and required dedicated staff.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 09:27:08 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Do-you-use-any-tool-that-does-automated-log-reviews/m-p/40639#M181</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2020-11-09T09:27:08Z</dc:date>
    </item>
    <item>
      <title>Re: Do you use any tool that does automated log reviews?</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Do-you-use-any-tool-that-does-automated-log-reviews/m-p/40640#M182</link>
      <description>&lt;P&gt;Found this on the net, might help you when doing your requirements:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://stackify.com/best-log-management-tools/#:~:text=The%20McAfee%20Enterprise%20Log%20Manager,%2C%20Application%2C%20and%20System%20logs" target="_blank"&gt;https://stackify.com/best-log-management-tools/#:~:text=The%20McAfee%20Enterprise%20Log%20Manager,%2C%20Application%2C%20and%20System%20logs&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;d&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 09:48:52 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Do-you-use-any-tool-that-does-automated-log-reviews/m-p/40640#M182</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2020-11-09T09:48:52Z</dc:date>
    </item>
    <item>
      <title>Re: Do you use any tool that does automated log reviews?</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Do-you-use-any-tool-that-does-automated-log-reviews/m-p/41146#M185</link>
      <description>I second what this individual stated regarding Splunk and Alienvault (although it looks like AT&amp;amp;T has bought Alienvault). I've personally seen more instances of Splunk being used. However, the ongoing challenge with Splunk (and likely Alienvault as well) is tuning the SIEM so it performs the activities both effectively and efficiently.</description>
      <pubDate>Tue, 01 Dec 2020 03:39:46 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Do-you-use-any-tool-that-does-automated-log-reviews/m-p/41146#M185</guid>
      <dc:creator>Titan</dc:creator>
      <dc:date>2020-12-01T03:39:46Z</dc:date>
    </item>
  </channel>
</rss>

