Log management review: LogRhythm LR2000-XM

The well-rounded LogRhythm XM appliance is feature-rich and flexible, from log collection to analysis

Another solution that combines log management and event management functionality, LogRhythm's XM appliance is long on features and flexibility. It combines a wealth of data views, easy pivot tables, viewing and filtering of real-time data, and the ability to enhance both discovery and analysis with strong Active Directory integration.

LogRhythm sent its 2U high LR2000-XM (version 5.0) appliance with two quad-core Intel Xeon 2.53GHz processors, 24GB of RAM, four internal NICs, and an eight-drive RAID array with 2TB of storage (the max is 8TB). The LR2000 is a little different than its competitor appliances in that it runs 64-bit Microsoft Windows Server 2003 R2 SP2 instead of a Linux or Unix distro. In place of a Web interface, you manage the appliance by connecting to it locally or using RDP and starting the LogRhythm console program.

The install is slightly more cumbersome than the competition, requiring a Windows setup and activation, two licensing files, and some minor INI file editing. LogRhythm technical support can walk you through the whole process in 30 minutes.

LogRhythm XM: Log collection and management

The feature-rich console contains hundreds of options, although day-to-day operations will usually consist of clicking on various graphics and typing in keyword search queries. The menu options change depending on the user type, of which there are three: Global Admin, Global Analyst, and Restricted Analyst. A Global Admin enjoys full control over the system. A Global Analyst can manipulate data from any source, print all reports, and configure a narrower set of options. A Restricted Analyst can be limited to seeing and manipulating particular event sources. This is a nice feature that allows administrative duties to be carved up based on responsibilities and expertise.

The LogRhythm console, like the other appliances, shows operational stats and event log information. It stands out from the crowd in the amount of information it displays on a single screen and the ability to check on multiple other appliances from the same interface. Event sources can be added manually in a variety of ways or, in some cases, by using active scanning tools.

