GFI EventsManager – Event Monitoring, Archiving & Management


You may remember a while back we reviewed the latest update of GFI LANguard 9, another powerful product developed by GFI is EventsManager.

Managing, archiving and monitoring logs and SNMP traps for a whole network can be a bit of a logistical nightmare, that’s where products like this come in. Commonly they are known under the umbrella term Business Intelligence Systems or more specifically Log/Event Management.

Installation is easy enough as per usual with GFI software, configuration will be a little more complex depending on the architecture of your network. If you have any problems however you can download the user manual here – esm8manual.pdf [PDF]. Do note you will require a local or remote instance of MS-SQL for events archiving. You can download and use MS-SQL 2005 Express Edition (which is free).

You can find an overview of the software here and a full features list here.

Once you get started you’ll need to setup the MS-SQL database before you can do anything else, so either put the details for your remote server or install the free express edition then set up the database.

GFI EventsManager

After that you can select if you wish to process local computer events, selected machines or setup custom config (snmp traps/syslog). There are a lot of options in the configuration management and allows you to easily aggregate the logs/SNMP output from a whole network. It allows logging from a plethora of devices including Windows and Linux servers, Cisco devices, Juniper devices, laptops, desktops and databases.

Config Manager

The main screen gives you a very simple overview that the services are running correctly and the global events count with a break-down by type.


Status Screen

The graphing view allows you to visually see by source or globally by event classification and volume flow by hour.

Graph View

The Event Browser allows you to view individual events, drill down to the details captured and sort them by status allowing you to track down problems easily and diagnose which application is causing the problem.

Event Browser

You can also add the free GFI EventsManager ReportPack, which enables you to generate graphical IT-level, technical and management reports based on the hardware and software events processed by GFI EventsManager.

Pricing runs as low as $45.00 per node for Servers and $4.50 per node for Workstations if you buy in bulk.

You can download the free trial here:

http://www.gfi.com/downloads/register.aspx?pid=esm

You can find the full details on GFI EventsManager here:

http://www.gfi.com/eventsmanager

Posted in: Advertorial, Countermeasures, Security Software


Latest Posts:


BloodHound - Hacking Active Directory Trust Relationships BloodHound – Hacking Active Directory Trust Relationships
BloodHound is for hacking active directory trust relationships and it uses graph theory to reveal the hidden and often unintended relationships within an AD environment.
SecLists - Usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells SecLists – Usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place.
DeepSound - Audio Steganography Tool DeepSound – Audio Steganography Tool
DeepSound is an audio steganography tool and audio converter that hides secret data into audio files, the application also enables you to extract from files.
2019 High Severity Vulnerabilities What are the MOST Critical Web Vulnerabilities in 2019?
So what is wild on the web this year? Need to know about the most critical web vulnerabilities in 2019 to protect your organization?
GoBuster - Directory/File & DNS Busting Tool in Go GoBuster – Directory/File & DNS Busting Tool in Go
GoBuster is a tool used to brute-force URIs (directories and files) in web sites and DNS subdomains (inc. wildcards) - a directory/file & DNS busting tool.
BDFProxy - Patch Binaries via MITM - BackdoorFactory + mitmProxy BDFProxy – Patch Binaries via MiTM – BackdoorFactory + mitmproxy
BDFProxy allows you to patch binaries via MiTM with The Backdoor Factory combined with mitmproxy enabling on the fly patching of binary downloads


Comments are closed.