• Home
    • ABOUT US
      • VISION
        • SOCIAL NETWORK>
          • FACEBOOK SECURITY
            • TWITTER SECURITY
              • SECURITY BLOG
                • SECURITY PRESENTATION
                  • JOIN LINKEDIN
                    • Ethical Hacking Blog
                    • PEOPLE
                      • CLIENTS
                        • CREDENTIALS
                          • MEDIA
                          • AUDIT
                            • WEBSITE SECURITY AUDIT
                              • APPLICATION SECURITY AUDIT
                                • NETWORK SECURITY AUDIT
                                  • PHYSICAL SECURITY AUDIT
                                  • Compliance
                                    • ISO 27001 IEC 27002 COMPLIANCE
                                      • HIPAA COMPLIANCE
                                        • ISO 20000 COMPLIANCE
                                          • PCI/DSS
                                            • TL 9000
                                            • SERVICES
                                              • PENETRATION TESTING
                                                • MANAGED NETWORK SECURITY
                                                  • MANAGED WEBSITE & APPLICATION SECURITY
                                                    • CONSULTING
                                                      • EMERGENCY RESPONSE & FORENSICS
                                                      • PRODUCTS
                                                        • SECURITY MONITORING
                                                          • GATEWAY SECURITY
                                                            • FORT APPIN ANTI-VIRUS
                                                              • aENCRYPT ENCRYPTION SOFTWARE
                                                              • Industry Focus
                                                                • Aviation & Airlines
                                                                  • Telecom & ISP
                                                                    • Education Sector
                                                                      • BFSI/Banking/Insurance
                                                                        • IT / ITES / BPO
                                                                          • E-Commerce
                                                                            • Government & Defense
                                                                              • Health Care & Life Sciences
                                                                                • Infrastructure
                                                                                  • Manufacturing & Engineering
                                                                                    • Media
                                                                                      • Retail & FMCG
                                                                                        • Security Articles>
                                                                                          • NETWORK SECURITY MANAGEMENT
                                                                                            • Information security companies
                                                                                              • WEB APPLICATION SECURITY>
                                                                                                • Wireless Pen Testing
                                                                                                  • Web Authentication Server
                                                                                                    • Web Application Testing
                                                                                                      • Web App Vulnerability
                                                                                                        • Web Application Monitoring
                                                                                                          • Application Server Monitoring
                                                                                                            • Application Vulnerabilities
                                                                                                              • website security audit
                                                                                                                • Application Security Assessment
                                                                                                                  • Application Penetration Testing
                                                                                                                    • Juniper firewall india
                                                                                                                      • Managed security services
                                                                                                                        • Security consultancy service
                                                                                                                        • NETWORK SECURITY>
                                                                                                                          • TCP IP Stack
                                                                                                                            • E-mail Password Encryption
                                                                                                                              • Block Port Problem
                                                                                                                                • Secured E-mail Server Hosting
                                                                                                                                  • Infosec Phishing Protection
                                                                                                                                    • Information Security Policy
                                                                                                                                      • IT Security Management
                                                                                                                                        • Intrusion Prevention System
                                                                                                                                          • Intruder Detection System
                                                                                                                                            • Internet Security Firewalls
                                                                                                                                              • Identity Access Management
                                                                                                                                                • Security Event Log
                                                                                                                                                  • Cyberoam Firewall
                                                                                                                                                    • Network Security Software
                                                                                                                                                      • Antivirus Firewall Software
                                                                                                                                                        • Symantec Antivirus Corporate
                                                                                                                                                          • Sonicwall firewall
                                                                                                                                                            • Online antivirus
                                                                                                                                                              • Best antivirus 2012
                                                                                                                                                                • Hardware Firewall
                                                                                                                                                                  • Internet software security suites
                                                                                                                                                                  • Industry>
                                                                                                                                                                    • Bank Online Application Security
                                                                                                                                                                      • Healthcare Hipaa Compliance Security
                                                                                                                                                                        • Banking Financial Risk Management
                                                                                                                                                                        • CONSULTING AND AUDIT>
                                                                                                                                                                          • Security Risk Consultant
                                                                                                                                                                            • Enterprise IT Security
                                                                                                                                                                              • Corporate Risk Management
                                                                                                                                                                                • Audit ISO 9001
                                                                                                                                                                                  • ISO 27001 Compliance
                                                                                                                                                                                    • Auditor Wireless Security
                                                                                                                                                                                      • PCI Compliance Credit Card
                                                                                                                                                                                        • Network Security Scanner Scan
                                                                                                                                                                                          • Risk Assesment Management
                                                                                                                                                                                            • ISO 20000 IT Service
                                                                                                                                                                                              • ISO 27001
                                                                                                                                                                                                • TL 9000 telecom
                                                                                                                                                                                                • Data security>
                                                                                                                                                                                                  • XSS Cross-Site Attack
                                                                                                                                                                                                    • SQL Injection Database
                                                                                                                                                                                                      • Database File Encryption
                                                                                                                                                                                                        • VPN HTTPS System
                                                                                                                                                                                                          • IP Spoofing Data Privacy
                                                                                                                                                                                                            • Man In Middle Attack
                                                                                                                                                                                                              • Data Loss Prevention
                                                                                                                                                                                                                • Data Protection Act
                                                                                                                                                                                                                • Appliance>
                                                                                                                                                                                                                  • Voip Voice Encryption
                                                                                                                                                                                                                    • IDS IPS UTM Appliance
                                                                                                                                                                                                                      • Load Balancer Bandwidth Manager
                                                                                                                                                                                                                        • Managed Firewall Services
                                                                                                                                                                                                                          • Cisco Mars Pix
                                                                                                                                                                                                                            • Firewall Web Server
                                                                                                                                                                                                                              • Firewall For Windows Server
                                                                                                                                                                                                                          • SECURITY GROUP
                                                                                                                                                                                                                            • Fort Appin Authorized consultant>
                                                                                                                                                                                                                              • Security-Consulting-Hyderabad-Himayath Nagar
                                                                                                                                                                                                                                • Security-Consulting-Hyderabad-Secunderabad
                                                                                                                                                                                                                                  • Security-Consulting-Rajasthan-Kota
                                                                                                                                                                                                                                    • Security-Consulting-Hyderabad-Ameerpet
                                                                                                                                                                                                                                      • Security-Consulting-Bangalore-JP Nagar
                                                                                                                                                                                                                                        • Security-Consulting-Hyderabad-Dilsukhnagar
                                                                                                                                                                                                                                          • Security-Consulting-Bangalore-Sahakarnagar
                                                                                                                                                                                                                                          • STUDENT TRAINING
                                                                                                                                                                                                                                            • SECURITY FRANCHISE
                                                                                                                                                                                                                                              • CORPORATE SECURITY>
                                                                                                                                                                                                                                                • FORT APPIN ANTIVIRUS
                                                                                                                                                                                                                                                • CYBER INVESTIGATION>
                                                                                                                                                                                                                                                  • INVESTIGATION FRANCHISE


                                                                                                                                                                                                                                                Security Event Log

                                                                                                                                                                                                                                                Event logs are a valuable tool to monitor network security and performance that are often underutilized due to their complexity and volume. As organizations grow in size, they require a more structured approach towards event log management and retention. A recent survey carried out by SANS Institute found that 44% of system administrators do not keep logs more than a month.

                                                                                                                                                                                                                                                Proper event log management helps you to meet several objectives including:

                                                                                                                                                                                                                                                Information system and network security System health monitoring Legal and regulatory compliance (SOX, PCI DSS, HIPAA) Forensic investigations

                                                                                                                                                                                                                                                Purpose of the event log in today’s network security environment. This topic came about to solve an every day business problem. Simply,there is not enough time in the day to perform all security analyst tasks and adequately monitor all network security devices. However, expectations were that monitoring all components of network security is essential. It’s the way things had been done and anything short of that may render a device or component of network security as ‘insecure’. It was clear that something must be done.
                                                                                                                                                                                                                                                The event log was chosen because the event log with proper auditing turned on was once the staple of detecting entry into a computer system. A failed logon attempt may indicate an attempt to gain unauthorized access. A successful logon may reveal the identity of a wrong doer in the event an unauthorized activity occurs. In addition, time was already being spent monitoring the newer technologies including the intrusion detection systems, but the event logs were no longer being reviewed. They were just put on a shelf.
                                                                                                                                                                                                                                                This topic is also relevant because more and more companies are implementing additional network security systems such as intrusion detection systems, network monitoring tools, host based intrusion detection systems, firewalls, and the list could go on and on. We are a very security conscious corporation that incorporated network security products aggressively. If we are struggling with monitoring, other smaller and newer companies must be as well. If the result
                                                                                                                                                                                                                                                of this research helps others make sense of monitoring and put it into perspective, it has been worth it.
                                                                                                                                                                                                                                                I would like to begin by providing a brief overview of the event log - its function and limitations.
                                                                                                                                                                                                                                                From there, I would like to discuss some of the components of network security focusing on server monitoring. Finally, I will provide discuss network security, and then end with identified issues and solutions and finally a conclusion.

                                                                                                                                                                                                                                                The event log consists of the system log, the security log, and the application log. They are called Sys.Event.Evt, SecEvent.Evt, and AppEvent.Evt respectively. They reside in the %systemroot%\system32\config folder. The purpose of the logs is to store information about problems, performance, and most importantly security as defined in the account and audit
                                                                                                                                                                                                                                                policies. In a 4/4/99 article entitled ‘The Event Logs’, the logs were described as follows:
                                                                                                                                                                                                                                                “System Log: The System Log contains events pertaining to NT’s services and drivers. If a
                                                                                                                                                                                                                                                service hangs upon starting, it will be recorded in this log. In a networked setting, there will
                                                                                                                                                                                                                                                often be “browser” events in this log, as the machines on the network vote on who will maintain
                                                                                                                                                                                                                                                the browse list.
                                                                                                                                                                                                                                                Security Log: When auditing is enabled, security events will be logged to the Security Log.
                                                                                                                                                                                                                                                Auditing is enabled via User Manager, printer properties, or file/folder properties. Administrator
                                                                                                                                                                                                                                                privileges are required to view the Security Log.
                                                                                                                                                                                                                                                Application Log: The Application Log is used for events generated by applications. This log can
                                                                                                                                                                                                                                                grow quite large when certain applications such as SQL Server or Exchange are running.
                                                                                                                                                                                                                                                Events will always be one of five types: Error, Warning, Information, Success Audit and Failure
                                                                                                                                                                                                                                                Audit (the last two in the Security Log)” [1]
                                                                                                                                                                                                                                                Reviewing these event logs without a third party tool is a lengthy and cumbersome process. It entails pulling up the event viewer and manually looking through each of the three logs for each server. This becomes repeated several times or hundreds of times depending upon the number of servers in your company and also based on the frequency of reviews. In addition, the events that you want to see are scattered in amongst many other events. This requires an additional search to find the events that you want to see. It is easy to see how this process may get put aside for more rewarding tasks to be completed.

                                                                                                                                                                                                                                                Article source: http://www.extralan.co.uk/products/Network-Security/GFI/Gfi-selm.htm
                                                                                                                                                                                                                                                Article source: http://www.sans.org/reading_room/whitepapers/windows/event-logs-defining-purpose-todays-network-security-environment_279