| Log analysis |
Pattern recognitionLOGalyze contains Log Definitions for several infrastructure and application level logs and audit trails. LOGalyze uses these Log Definitions to identify, parse, normalize and index the incoming messages. Log normalizationLOGalyze converts the parsed fields into a normalized format for analysis and reporting purposes. If systemsin your organizations are spread across time zones LOGalyze automatically converts the timestamps into GMT. Time synchronization helps you to correlate logs from different locations. Prioritization, classification and taggingLog Definitions help you to order messages in different classes or tag them with different keywords for later usage. Correlation analysisThe LOGalyze Correlation module is collecting messages from different systems and finding all the messages belong to one single event (E.g. messages generated by malicious activity on different systems: network devices, firewalls, servers etc.). LOGalyze supports the following types of correlation:
The correlation module can produce output by sending email, snmp traps, calling external programs. Artificial ignoranceLOGalyze can detect the anomalies in a working system. Tthis means recognizing and ignoring the regular, common log messages that result from the normal operation of the system, and therefore are not too interesting. However, new messages that have not appeared in the logs before can sign important events, and should be therefore investigated. Event managementLOGalyze can process its internal synthetic events, audit logs such as any external log data. You can define reports on internal events, create Event Definition to alert or simply search on them. |

