Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Clear Choice Test

Security Information and Event Management

Introduction|Are SIEM and log management the same thing?|Scorecard|How we did it|Slideshow|Test archive

CheckPoint's SIEM software offers some good data viewing tools, but lacks other essential elements

By Greg Shipley , Network World , 06/30/2008
  • Share/Email
  • Comment
  • Print

Editor's note: This is a summary of our testing of this product, for a full rundown of how it fared in our testing across SIEM categories; please see our full coverage.

CheckPoint's Eventia is delivered similar to many of its other products as either a full-blown hardware appliance or as a "software appliance", which is essentially a CD set that installs a fresh Linux-based operating system (as modified by CheckPoint, of course) and the Eventia application on a range of Intel-based systems. CheckPoint delivered us a full-blown appliance for testing, but we also played around with the CDs themselves and found that the initial install of those would most likely be a cake-walk for just about any seasoned IT professional.

Eventia, like NetIQ's Security Manager, contains the basic components of a SIEM but falls behind in some feature areas we consider essential such as advanced reporting, strong support for non-CheckPoint devices and overall event reduction.

Unlike Security Manager, however, we were able to get Eventia up and running in less than one day. Eventia requires the installation of a number of Windows-based clients for administration including the Smart Dashboard, the SmartView Tracker and the Eventia Analyzer.

Eventia includes a healthy set of predefined correlation rules and to CheckPoint's credit, it's easy to get into the rule logic and see what the rules are doing. Eventia does require you to use different tools, however, even for performing sub-tasks of a common task. For example, the Eventia Analyzer is where you view correlated alerts. But if you want to view the raw log data that caused an alert, the Analyzer has to launch the SmartView Tracker tool. We'd prefer to drive the majority of event analysis from one tool, but to CheckPoint's credit the tools are successful at launching one another and placing you in the right spot.

CheckPoint also has a rather nice tool for building custom event handlers, helpful for the creation of devices that Eventia doesn't yet support or custom applications.

Eventia comes up a bit short in a few areas, however. For starters, its reporting system is really limited and when it comes to canned reports, it only includes a few default ones that cover non-CheckPoint devices. It also doesn't have any ability to rate or group assets, something that is one of the most basic of SIEM features. Its dash-boarding features aren't as comprehensive as those found in High Tower or Q1 Labs' products, and the event reduction is a start but we were still inundated with hundreds of events.

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.
Network World,to go. Wherever you are. Breaking news delivered to your mobile device. Select the hottest topics in networking and start receiving Network World on your mobile device today.