Changes

Bxp and Security Event Management solutions

1,039 bytes added, 20:18, 11 May 2015
no edit summary
This article and feature bxp recognises that there are a number of Security Event Management solutions available on the market. bxp are in developmentis able to integrate solutions at a number of levels to facilitate consistent centralised monitoring and control.
 The primary requirement of integration is to decide the level of integration.  Identifying and classifying security events is the primary stage.  With the events identified and classified integration a project is implemented to facilitate your requirements for live logging.  Events will always come from static IP addresses within the bxp platform to facilitate whitelisting.  * HP ArcSight** https://protect724.hp.com/docs/DOC-10613  * Logly** https://www.loggly.com/docs/restful-api/  * Logstash** http://logstash.net/docs/1.4.2/outputs/elasticsearch  * Papertrails** http://help.papertrailapp.com/kb/how-it-works/http-api/  * Splunk** http://dev.splunk.com/view/rest-api-overview/SP-CAAADP8  * Splunk>Storm** http://docs.splunk.com/Documentation/Storm/Storm/User/UseStormsRESTAPI  * Sumo Logic** https://github.com/SumoLogic/sumo-api-doc/wiki  [[Category:To Be RevisedTopic:Security]]
[[Category:Topic:Scenarios]]
7,528
edits