Features
Highly Refined Compliance Reports on Key Security Events of Your Network
Often there is some confusion among users as to which event reports are needed for meeting the requirements of different compliance acts. GFI EventsManager solves this problem by providing you with specific reports for some of the major compliance acts as well as other standard reports, including:
- Payment Card Industry (PCI DSS) reports
- Code Of Connection reports
- HIPAA reports
- SOX reports
- Account Usage Reports including users who deleted files report
- Account Management reports
- Policy Changes reports
- Object Access reports
- Application Management reports
- Print Server reports
- Windows Event Log System reports
- HTTP traffic monitoring report
- Events Trend and Service Status reports
- Deleted files report
- Service Status report
GFI EndPointSecurity Data Integration
GFI EventsManager offers dedicated processing rules, available out-of-the-box, that allow users to automatically categorize, report and alert on the events generated by GFI EndPointSecurity. These events are also present in different reports which are useful both for network monitoring and regulatory compliance purposes.
For those who also have GFI LANguard, GFI EventsManager can also process that productâs results to offer an enhanced compliance reporting experience by providing the necessary compliance information in a single location.
Centralized Event Logging
Event logs are constantly and automatically generated by a user or by an automatic or background process. Logs are often stored in disparate locations. GFI EventsManager stores all captured event logs into one SQL database that may even reside remotely. Through GFI EventsManager you can configure scheduled backups of your event logs.
Analysis of Event Logs including SNMP Traps, Windows Event logs, W3C logs, SQL Server Audit Logs and Syslog
As a network administrator, you have experienced the cryptic and voluminous logs that make log analysis a daunting process. GFI EventsManager is a log processing solution that provides network-wide control and management of Windows event logs, W3C logs, SQL Server audit logs and Syslog events generated by your network sources. GFI EventsManager supports Simple Network Management Protocol, the language spoken by low level devices such as routers, sensors, firewalls, etc. Through SNMP users can monitor a whole range of hardware devices on their infrastructure and gain the ability to report on the health and operational status of each device.
Auto-archive All Events into Files
Due to the relatively large number of events that must be kept for investigation and compliance purposes, it takes no time for the events database to reach its maximum capacity. To alleviate this issue, GFI EventsManager allows administrators to auto-archive all events into files in parallel with processing the events through rules with important events only being saved into the database. Moreover, GFI EventsManager features the rollover backup databases which automatically trigger and manage the backup process.
Powerful Dashboard
The GFI EventsManager dashboard includes a number of filtering-enabled charts to provide administrators with fast and easy access to the data they need as they go about their day. These include the top critical and high importance rules triggered within a certain period of time, the top 10 users who fail to log on or who log on during and outside working hours, service status across network, how many events are stored in the database per log type and a comprehensive graph based on Windows events that shows network connections at application and user level (available for Vista and newer Windows OSs only). The dashboard is highly customizable and can be zoomed individually in separate windows that can be automatically arranged on the desktop to show real time data about the most important events.
One-click Rule and Filter Creation
You can create processing rules and filters for Windows events by simply right-clicking on event details in the Events Browser Tool. New rules are automatically saved into a new rule set called User Rules and will have the least priority by default.
Real-time Alerts, SNMPv2 Traps Alerting Included
GFI EventsManagerTM has improved alert level for key events or intrusions that are detected on the network. GFI EventsManager allows you to trigger actions such as scripts or to send an alert to one or more people by email, network messages, SMS notifications sent through an email-to-SMS gateway or service and includes SNMPv2 traps. The generation of SNMP alerts will also allow administrators to integrate GFI EventsManager with pre-existing or generic monitoring mechanisms.
Password Recovery
GFI EventsManager enables a password reminder email to be sent to the administratorâs registration email address should they lose or forget it.
Detection of Windows Events that Refer to Administrators
GFI EventsManager can detect if a Windows event refers a user who is an administrator user, a feature that is required by certain regulations. GFI EventsManager checks the details of events and probes whether the user names or SIDs in question correspond to administrator users. The product can also track changes in rights assignment (through Windows Events) so that if a user becomes or stops being an administrator by the time an event has been generated, GFI EventsManager will report accordingly. To use this feature in domains, one must scan the domain controller before scanning other machine members.
Certified for Windows Server 2008; Supports Windows 7
GFI EventsManager has achieved âCertified for Windows Server 2008 and Windows Server 2008 R2 status and can be installed on, and collect events from Windows 7, Vista and 2008. Although these new platforms use a different log format, GFI EventsManager presents events from various operating systems in the same manner, thus allowing the user to see a common structure, regardless of the platform being monitored. GFI EventsManager also supports Windows 2000, Windows XP, Windows 2003 and Windows 7.
GFI EventsManager Audit for Windows
GFI EventsManager offers an audit system for Windows machines. It works through a scanning system based on checks which are pre-programmed. When a regular log scan is started on a Windows computer, EventsManager Audit, when enabled, will execute all the selected checks. Once checks are done, their results will be written as events in the Windows application log of that machine or the local machine. After the audit, the usual log scanning will start and the new audit events will be available for processing too. Event processing rules can be defined to process the result of the checks. For instance, users can be alerted when a certain check has failed. These results can also be displayed on the dashboard showing the âhigh importanceâ events.
Through the GFI EventsManager Audit one can discover if there are:
- Inactive users (users who havenât logged on during the last 30 days)
- Inactive machine members in a domain (machines not used during the last 30 days)
- IPSec policies not active
- Microsoft firewall products installed and not active
- Slow responses to PING
- Disk volumes running out of space
Deeper Granular Control of Events
GFI EventsManager helps you monitor a wider range of systems and devices through the centralized logging and analysis of various log types including Windows events, Syslog, W3C and SNMP traps that are generated by network resources. Administrators can gather information from Windows machines and third-party devices at a greater level of granularity and process information at extended tags level, basing the decision of what to do with that information on the spot, without further information management.
Computer Discovery and Domain Synchronization
It is possible to configure GFI EventsManager by automatically detecting computers from the network or by automatically synchronizing computer groups with computers from domains.
Support for New Devices
Managing SNMP Trap for myriad devices requires the ability to understand the language each manufacturer uses to define events. These definitions and the device information are contained in Management Information Base (MIB) definition files, provided by the manufacturers. GFI EventsManager ships with MIB definitions for the following vendors: Cisco, 3Com, IBM, HP, Check Point, Alcatel, Dell, Netgear, SonicWall, Juniper Networks, Arbor Networks, Oracle, Symantec, Allied Telesis and others. GFI EventsManager is capable of importing the MIB files.
SQL Server Auditing
GFI EventsManager supports SQL server auditing for all commercial and free versions of SQL Server including 2000, 2005, 2008, MSDE and SQL Express. Auditing allows the user to track and report on SQL server activity such as: Running of SQL statements, altering DB tables, attempts to access data without necessary privileges, etc. This can ensure data in SQL servers is authentic and thus reliable.
New! Oracle Audit Support
Many companies use Oracle database servers and the activity on these servers need to be monitored for security or regulatory compliance purposes. GFI EventsManager can process Oracle audit records for versions 9i, 10g, and 11g.
Translates Cryptic Windows Events
Cryptic logs make log analysis a painful and lengthy process. GFI EventsManager translates those event descriptions to clear, concise explanations and suggestions for action.
High Performance Scanning Engine
GFI EventsManager incorporates a totally redesigned event scanning engine that is fine-tuned for maximum scanning performance. Tests demonstrate that our engine is able to scan and collect up to six million events per hour. Its plug-in based methodology allows additional features and modules to be integrated without interfering with existing code.
Collect Events Data Distributed Over a WAN into One Central Database
You can collect events data from GFI EventsManager installations on multiple sites and locations across your network into one central database using the Database Operations functionality. This enables you to easily monitor thousands of workstations and servers across the network without impacting bandwidth and storage use. It integrates and centralizes events collected and processed and allows you to backup and restore events on demand. Through database operations you can manage the size of the database – without the need for manual intervention – not only by centralization but by also being able to export events and back them up as needed.
New! Export Events into Customizable HTML files
GFI EventsManager can export events from the event browsers into HTML format, based on templates which can be customized. These templates make it possible to choose the columns for reporting and perform column mappings. The layout of the HTML template can also be customized by editing the corresponding .css file.
Rule-based Event Log Management
GFI EventsManager ships with a pre-configured set of log processing rules that allow you to filter and classify events that satisfy particular conditions. You can either run these default rules without performing any configuration, or you can choose to customize these rules and create tailored ones that suite your network infrastructure.
Advanced Event Filtering Features
GFI EventsManagerâs powerful filtering sifts through recorded event logs allowing you to browse without deleting any records from your database backend. You may also selectively highlight specific events using a color or the integrated event finder tool.
Event Log Scanning Profiles
Scanning profiles allow you to configure the set of event log monitoring rules that will be applied to a specific computer or to a group of computers. Profiles provide a centralized way of tuning event log processing rules. You can, for example, set up a set of rules that only apply to workstations in a particular department. Or you might create separate complementary profiles that provide additional and more specialized event log rules on a computer by computer basis.
Helps You to Comply with PCI DSS and Other Regulations
Data logging is key to meeting the requirements of different compliance regulations like: Payment Cards Industry (PCI DSS) Standard, HIPAA, FISMA, GLBA and others. All businesses handling cardholder data, regardless of size, must be fully compliant with strict security standards drawn up by the worldâs major credit card companies. Logs provide audit trails of all activities in a credit card holder data environment and hence, a comprehensive log management system, such as GFI EventsManager, is what you need to be PCI DSS compliant. The GFI EventsManager ReportPack also contains reports specific to PCI DSS.
Support for Virtual Environments
Organizations that are currently using or plan to use virtualization on their network can still install and use a range of GFI products with confidence. GFI EventsManager supports and runs on the most common virtualization technologies in use, namely VMware, Microsoft Virtual Server and Microsoft Hyper-V.
Other Features:
- Remove ânoiseâ or trivial events that make up a large ratio of all security events
- Real-time 24 x 7 x 365 day monitoring and alerting
- Report scheduling and automated distribution via email
- Auto-refresh option for browsing events
You're in Great Company...
Thousands of companies have chosen GFI EventsManager.