|
Event Collection Manager
Aggregates Different Event Information
Since few standards exist today in the
world of information security, security devices themselves
do not adhere to common criteria when producing security event
information. So, while multi-vendor firewalls and IDS / IPS
may perform a similar function, their event information looks
very different. Event Collection Manager helps in normalization
and handles cross-product security alarms and event logs into
single normalized dataset for correlation analysis and visualize
in a single management console.

 |
 |
Device Diagram |
|
Administrators first connect different security devices which logs and events need to be received by Incident MiND. After receiving logs and events, Incident MiND will carry out a process called Normalization to normalize all the logs and events which are originally in different formats. This process makes the data becoming same format and allows them to be further correlated and analyized by Incident MiND.
|