- Is the Cisco MARS mission going to abort?
- First iPhone worm spreads Rick Astley wallpaper
- 10 stunning 3D buildings made with Google SketchUp
- Open source software ready for big business
- Four reasons to buy (and one reason to avoid) the Droid
Almost all components of a data center such as network devices, storage systems, servers and even the electrical systems generate logs. Like a central nervous system, log messages are generated by these devices using the syslog or SNMP protocols apprising us of various activities and events at the hardware level (for example, data link down, fan failed), operating system level (disk full, too many files open) or at the user level (user logged in, incorrect password).
To take advantage of this flow of information, data center architectures must include the necessary infrastructure to collect, filter, analyze, correlate and archive the log information. Data center managers can put log data to many uses such as troubleshooting, security monitoring, network management and regulatory compliance. The operations and security groups will use logs in slightly different ways, so the infrastructure has to be flexible enough to support these different uses.
For security monitoring, the emphasis is on finding the "needle in the haystack" through filtering and correlation in near real-time. As thousands of messages stream in from various devices, the log management infrastructure must be able to prioritize and alert on the most important messages without overwhelming the operators. The term "Security Information Management" is used to describe a range of products from vendors such as Arcsight, Netforensics, Intellitactics and Micromuse, which provide this type of functionality. These products specialize in intelligent filtering and the management of large volumes of messages to provide selected alerting with a focus on security.
Network monitoring and troubleshooting require sophisticated filtering of log data, with the addition of root-cause analysis. HP OpenView, IBM Tivoli and other such products focus on providing an overview of the data center and network to assist the operations group in maintaining availability and performance. Root-cause analysis is the process of correlation that allows operators to identify the underlying event that may have triggered a wave of log messages across the infrastructure.
Regulatory compliance has become an increasingly onerous responsibility for many enterprises, especially in the health and financial services sectors. Regulations such as Sarbanes-Oxley, the Health Insurance Portability and Accountability Act and Gramm-Leach-Bliley Act stipulate that enterprises must monitor their infrastructure and retain audit data on the activities of their users and administrators. By securely collecting and archiving logs for long-term storage, enterprises can meet many of these regulatory requirements. To comply with the regulations the emphasis must be on collecting "raw" log data (without filtering) and on long-term archival. The log archives must be securely stored and searchable for forensic and investigatory purposes. Vendors such as Addamark and Loglogic offer products focused on archival for compliance purposes.
Partner Content
www.bmc.com
Gartner 2009 Magic Quadrant for Job Scheduling
Gartner has positioned BMC CONTROL-M in the Leaders Quadrant of their "2009 Magic Quadrant for Job Scheduling." The report assesses the ability to execute and completeness of vision of key vendors in the marketplace. Read a full copy today, courtesy of BMC Software.
Download whitepaper
Dell's SMART Approach to Workload Automation
Read a compelling case study by EMA, Inc. to learn how Dell uses BMC CONTROL-M to cut cost and increase productivity with workload automation.
Download whitepaper
Workload Automation Cost Savings 2 Minute Video
A major computer manufacturer uses BMC CONTROL-M and just four people to schedule and run over 85,000 jobs every month. By switching to BMC CONTROL-M, they more than quadrupled the workload without adding a single staff member. See how in this 2-minute video overview.
Go to video
Comment