Surfilter Log Management Integrated Audit System (Logbase) is a professional information security audit product with independent intellectual property rights developed by Surfilter. It monitors and collects system security events, user access behavior, system operational logs, system operational status and other information in the system. After processes such as standardization, filtering, merging and alarm analysis, centralized storage and management are performed based on a unified log format, combined with rich statistical log summary and comprehensive analysis functions. This ensures overall audit of the entire information system’s security status.
Product Functions
Log Data Collection
Conducted through various log collection methods that do not interfere the audit object, Logbase collects almost all kinds of log data in the information system.
Real-time Kinematic (RKT) Analysis
Data merging, correlation analysis, three-layers analysis, feature filtering, knowledge base.
Secure Storage Management
LogBase adopts a dedicated hardware platform as well as streamlined and optimized operating system, ensuring the security of the underlying audit system. LogBase is equipped with a system firewall and contains storage space which adopts Raid5 storage architecture and dedicated log storage system (Universe file software system), ensuring security of log data storage. Log anti-tampering and anti-deletion functions are designed in the system, ensuring that the original log data cannot be modified. LogBase supports offsite manual log data backup and automatic archival function. The archived file is encrypted and stored, in order to guarantee data integrity, security and availability.
Historical Event Retrieval
LogBase supports multiple criteria combinations such as content-based keywords, source (target) IP address, user, time, operation keywords, etc., which provide quick retrieval and accurate location of historical events. LogBase supports query template customization, making it convenient for users to create templates to retrieve events they are interested in on a regular basis. LogBase supports cluster rendering by protocol and export function of query results, which facilitates verification by users.
Comprehensive Audit Report
LogBase provides rich compliance report templates (e.g. SOX Act, classified protection), to meet daily audit requirement of users. The system supports manual/automatic report function, which can be used to not only generate reports based on multiple criteria combinations, but also automatically generates daily, weekly, monthly, quarterly, yearly, and other comprehensive reports. It also supports self-defined normal report module customization, and the reports can be exported to MS EXCEL, HTML and other formats, ensuring all-dimensional and multi-angle audit of the database system, database server, and relevant network device security.
Product Features
Comprehensive log collection
Reliable safety guarantee
Dedicated expert log rules base
Flexible and open query criteria
Effective event location
Safe bypass audit mode
Good scalability
Rich compliance reports