Cisco Nexus Dashboard simplifies data-center networks with automation and analytics. The data-center network helps organizations to meet business demands, and provision reliable data-center networking services as fast as possible, when and where organizations need it. As network infrastructure management is becoming more complex, diverse, and distributed, with multiple configuration points, monitoring tools, and vast amounts of data being generated every second. Cisco Nexus Dashboard is…
N/A
LogRhythm NextGen SIEM Platform
Score 6.6 out of 10
N/A
The LogRhythm NextGen SIEM Platform, from LogRhythm in Boulder, Colorado, is security information and event management (SIEM) software which includes SOAR functionality via SmartResponse Automation Plugins (a RespondX feature), the DetectX security analytics module, and AnalytiX as a log management solution that centralizes log data, enriches it with contextual details and applies a consistent schema across all data types.
Nexus Dashboard is a vital tool for Cisco data center Nexus deployments, in my opinion. By utilizing multiple applications in the suite, a business can utilize orchestration, monitor services and traffic, test deployment scenarios, verify upgrade processes and readiness, etc. The capabilities of the system can allow for SAN MDS controls, traditional Nexus NXOS integration, and/or essential ACI tools
LogRhythm is good for providing a comprehensive view of the environment. It gives a great outline of whatever is going on in our servers and systems regarding security malfunctions. The SIEM sends real-time notifications when there are some occurrences; like creating a new user and inappropriate login attempts. It also avails a good use case that meets our HIPAA compliance.
LogRhythm NextGen SIEM Platform has an alarm system that generates tickets based on the event and the way it has been configured in the LogRhythm console. Let's say we have a ticket for a malicious email attachment. The ticket will some information like the source of the log, the source IP, destination IP etc. It can be drilled down to obtain specific information like the recipient, source location, file attachment name, SHA hash of the file, source and destination port, time, mac address of the machine that downloaded it etc. This helps the analysts to go to the root of the cause and take actions easily without manually parsing them.
The second good thing about the LogRhythm NextGen SIEM Platform is that it is very easy to use with its well-structured interface. To use LogRhythm, an user barely require any technical skills. A little overview of IP, CIDR, hash, etc. is enough to get your hands on it. It requires no programming or coding skills, as everything is GUI based. It also provides a beautiful visualization dashboard. There is another beautiful feature that it provides for the classification of events, known as cases. Multiple users working on the same platform can create cases and add events to it. They also help to maintain future reference.
The third good feature is the search tool which is very powerful. For example, sometimes it is hard to find the users who downloaded a malware from the guest wireless of the institution and not the private network. The search tool helps us in searching the user by automatically correlating the MAC address from the current network logs and the previous logs as the MAC address is the same. It is highly scalable for parsing a large number of logs from various sources.
I particularly think this is one of the best software available for log parsing in an organization where non-technical users are working on incident response. This tool has a good amount of flexibility. However, it can only be configured with the LogRhythm NextGen SIEM Platform Console.
In terms of usability, as already mentioned, it is a very easy tool to use, with a GUI based interface.
With the latest version release of Cisco Nexus Dashboard to version 3.0.1 I can say that most of the features have already improved but one of the wishlists that I want for ND is the possibility of extracting lists of Anomaly.
Include older versions of Firmware in the list of choices when doing the firmware upgrade analysis, currently only the recommended is in the list of choices.
If possible, include all the prechecks in the Firmware pre-upgrade analysis same in the script provided by Cisco.
LogRhythm absolutely needs to provide back end support for threat intelligence lists. Performing a linear search on massive lists of IPs on incoming web traffic can bring the SIEM to its knees.
LogRhythm should drop its entire code base for implementing lists and simply turn them into hash tables to avoid the excessive cost associated with referencing lists in rules. I haven't seen the code, but the performance suggests O(n).
The reporting feature is the worst of all SIEMs, luckily reports are not my primary service offering. LogRhythm should definitely revamp its reporting to be more intuitive.
LogRhythm is focused on SIEM. That is their core business. Cost of operations, feature set and ease of use. The Log Rhythm support team is outstanding. Overall reliability is good. Reporting module needs some improvement and LR is promising that there will be significant improvements in future releases.
For the end user, it is relatively easy to use. However, some training and practice is a must because the NSO is not as straightforward as the traditional router CLI. For the administrator, Cisco Network Service Orchestrator (NSO) is just like another program running on the Linux system--there is no big difference.
LogRhythm does a rather decent job of making the functionality advanced (allowing for advanced keyword & field searching, use of "AND" as well as "OR" statements in the search bar) while keeping it accessible (by not requiring a specific syntax to do quick searches). This combined with a user interface that has headings and labels that are intuitive is very helpful.
Great and effective automation functionalities and the tools on network security management are the best and easy data reports building. Cisco Nexus Dashboard Fabric Controller feature for the network monitoring and easy management of various services and even offers the best analytics and also powerful integration tools for easy data migration.
While LogRhythm support is generally quick to respond, the initial response is usually from a first line support engineer with general knowledge of the product. Any advanced or complex issues have always required the assistance of a higher tier of support, directly or indirectly. For a few occasions we actually used our PS hours to work on the issue.
The Cisco Nexus Series switches perform admirably in our blended distributed system. We have been dealing with any of these sorts of switches for over 5 years and have been exceptionally happy with their functionality. Several of our other computer networks in our data rooms have proved effective with Cisco equipment. Because of the simplicity of maintenance and the high quality of technical support provided by Cisco representatives, there is a high level of trust in these switches.
LogRhythm was simpler to set up and configure as well as extract information from. It also was less intrusive in terms of how many appliances were needed to implement. We were up and running within 5 hours to start accepting log sources. We selected LogRhythm as well since support is based in the USA in Colorado.
The platform is very well done, and to date, I have had no complaints about the implementation of the platform and no security issues or vulnerabilities. Cisco in all its product releases new versions to resolve security issues or bugs that appear on the platform, this is a big plus.
The ability to search through logs in a centralized location really helps us to provide RCA (Root Cause Analysis) to management for outages. This helps us to quickly identify the cause of outages and thus saves money due to reduced downtime.
Being able to configure the alarms to provide real-time notification (and responses) to security events helps to prevent potential loss due to compromises (such as a fraudulent wire transfer).
The initial investment in LogRhythm SIEM is somewhat expensive, however, the appliance is built to your specific needs so you won't have to constantly be upgrading the device as your company grows.