-
Research
and PublicationsStay -
Conferences
and EventsAnnual Conference
October 15–18, 2013
Register now!Events for all Levels and Interests
Whether you're looking for a conference to attend face-to-face to connect with peers, or for an online event for team professional development, see what's upcoming.
Stay -
Career
DevelopmentEDUCAUSE Institute
Leadership/Management Programs
Explore MoreCareer Center
Leadership and Management Programs
EDUCAUSE Institute
Advanced Programs
Project Management
Jump Start Your Career Growth
Explore EDUCAUSE professional development opportunities that match your career aspirations and desired level of time investment through our interactive online guide.
Stay -
Focus Areas
and InitiativesLatest Topics
EDUCAUSE organizes its efforts around three IT Focus Areas
Join These Programs If Your Focus Is
Stay -
Connect
and ContributeFind Others
Get on the Higher Ed IT Map
Employees of EDUCAUSE member institutions and organizations are invited to create individual profiles.
Stay -
About
EDUCAUSEUncommon Thinking for the Common Good™
EDUCAUSE is the foremost community of higher education IT leaders and professionals.
Stay
How Advanced Log Management Can Trump SIEM: Tales of Woe and Glory
Tuesday
Apr 16th, 2013
1:15 PM - 2:00 PM
Central Time
Salon B
Change Timezone
TIMEZONE
View this schedule in your local timezone (Pacific Time) or select a different location:
Session Type: Concurrent Session
Network situational awareness is a prerequisite for mature information security operations. Achieving and maintaining a sufficient level of situational awareness is a challenge, often amplified in higher education institutions having highly decentralized governance models. Application and system logs, even if available to an operational security group, have become less effective as the number of devices, services, and users has increased. The existing Security Information and Event Management (SIEM) solutions usually are too costly, time-intensive, or a poor fit for educational networks. Adelphi University replaced their SIEM with a log management platform and haven't looked back. Carnegie Mellon University uses open-source tools to index log data in near-real time and search terabytes of data in milliseconds, and a custom-built web interface lets analysts quickly drill down to unusual events.
















