Ascent Media Group has deployed an enterprise SIEM system that provides deep insight to what’s happening on its network that spans 60 semi-independent companies and 40 locations around the world. A single console in California provides alerts on problems that are happening half a world away.
When a server is sluggish in Singapore, or a virus invades in the United Kingdom, Californian Michael Chapman knows it almost instantly. No, he’s not the Server Psychic from the Science Channel; he just knows how to make good use of his log and event management tools.
Chapman is director of Digital Security and Technical Operations for the West Coast division of Ascent Media Group, a media conglomerate comprised of some 60 companies around the world. Chapman’s extra-long title means he serves multiple roles for his employer. His digital security role holds him responsible for network security and the protection of Ascent Media’s digital assets — which happen to be the company’s crown jewels. His technical operations role requires oversight of the corporate IT infrastructure, and by default, that makes him the guy responsible for IT compliance with the Sarbanes-Oxley Act (SOX).
11 security companies to watch
It was the need to meet SOX compliance that led Chapman to look for a log management system that could span the enterprise, which includes all 60 or so semi-independent companies. Because they are all under the Ascent Media corporate umbrella, their log data must be consolidated for SOX reporting purposes. That’s quite a challenge when the companies and their computing devices are in more than 40 facilities worldwide, in places such as New York, London, Singapore, Atlanta, and Burbank, Calif.
Chapman has found one security information and event management tool that serves his needs for all of his roles. Ascent Media uses LogRhythm log and event management appliances to meet their SOX compliance requirements and improve security and operations throughout the entire enterprise. Chapman chose LogRhythm because it is architected to support a geographically dispersed enterprise. I talked with him about how he uses this tool to gather log data from every far-flung device and bring it into an event console that he calls his “single pane of glass.” Through this console, Chapman can see any security or operations problem that requires attention.
Ascent Media’s solution is comprised of two types of components: a log manager and a console appliance called the event manager. The company has placed one log manager in each of its four major geographic locations (U.S. East Coast, West Coast, the United Kingdom and Singapore). The lone event manager console is in Burbank, Calif.
Each regional log manager receives all the log data from the agents installed on various devices within a geographic region. An agent is capable of reporting for itself locally on the box it is installed on, and it also is capable of doing remote collection from other devices. With this capability, Chapman says he doesn’t have to buy an agent for every single device. Instead, he can have an agent installed on a machine and have it remotely collect logs from devices that are in its vicinity.
The log data from all the field devices is consolidated at the log manager level, where it is classified according customizable rules. Anything that is classified as an “event” or an “alarm” is funneled through to the central event manager in California. An alarm is generally something that requires attention, such as a device failure. An event is something that may or may not be significant, but it warrants further watching or investigation. An example would be a SQL read error, which often resolves itself. In such a case, Chapman watches to see if numerous events pertaining to the same situation occur within a few minutes. If so, then there’s a genuine problem to investigate.
Once the events and alarms are sent to the event manager, Chapman has a view of his entire infrastructure. His team is currently going through the exercise of classifying the events that truly need attention and those that can simply be watched. The console can send out e-mail alerts, text messages and other signals to designated people to let them know of a problem. It also can create a trouble ticket in the event of an urgent alert.
Chapman says his biggest challenges is in figuring out how to threshold the alerts. In the case of that SQL read error, for example, it takes a little understanding to know when it’s a problem and when it isn’t. If you’re looking at a SQL database, sometimes the read queue gets out of synch with writing to the disk. SQL thinks this is a critical alert and that’s how the log data is classified. In most cases, however, the situation resolves itself within a few seconds or minutes. Chapman doesn’t need to be alerted on something that resolves itself, and he doesn’t want a trouble ticket opened. But if a similar alert occurs multiple times within a few minutes, Chapman wants the event manager to open a trouble ticket so someone can see if there’s a real problem with SQL.
Ascent Media originally bought LogRhythm in order to comply with SOX requirements to collect and retain logs. That certainly has been achieved, but the bigger benefit has come from the deep insight Chapman’s team now has into the infrastructure that spans the world. They’ve been able to reduce operational costs in terms of the man-hours spent investigating problems. Now the problems bubble up and are viewed through that single pane of glass, where Chapman can drill down to get to the root of the matter.




