| Secure's profileSecure Vantage Team BlogPhotosBlogLists | Help |
|
|
June 12 ISV Über Demo available for downloadToday we posted the recording of the System Center Operations Manager ISV Über Demo, ISV solutions for cross-platform monitoring, regulatory auditing and advanced visualizations. There are over forty minutes of demos and everything is running on SCOM R2! J This is a great session for Microsoft field, partners and SCOM users that shows real world examples of how to get the most out of your System Center investment leveraging native third party solutions like BridgeWays, Savision and Secure Vantage Technologies. Download Video – ISV Über Demo For those interested in more solution and training videos please visit our online knowledge base where we recently posted a video of our Security MP Templates and now have the entire ACS Master Class Series available for download. June 08 New ACS Master Class available for downloadToday we posted the final video in the ACS Master Class Series core sessions, Audit Policy Planning, presented by renowned Windows security expert and Microsoft Security MVP Randy Franklin Smith. Download – ACS Master Classes, Audit Policy Planning This is a great session with in-depth guidance on what an audit policy is, details on each Windows audit policy, changes with Vista and Windows Server 2008 audit policies, and lots of demos on how to apply the various policies within your environment. In this session you’ll also learn the differences between Account Logon and Logon/Logoff events, the pros and cons of Object Access auditing, how to apply sub category audit policies in Vista and Windows Server 2008 plus great tips on Directory Services and other types of auditing. So if you’re looking to implement an audit policy for the first time or want to improve how you audit your Windows environment this is the session for you. For those interested in more resources and training on Windows and Active Directory security check out Randy’s site, UltimateWindowsSecurity.com where you’ll find his online security log encyclopedia, WinSec Wiki and tons of other great security resources.May 15 ISV Über Demo, Webcast June 3rdThis year at MMS we held a great breakout session and showcased how System Center Operations Manager can be optimized with partner solutions to address cross platform monitoring, security and compliance plus enhanced visualizations. Given the feedback and community requests we decided to host two live webcasts next month on June 3rd, at 7am and 1pm PST, to redo the ISV Über Demo. Don’t miss this great opportunity to see firsthand how easily SCOM can be extended to address real world business problems, reduce complexity and TCO for IT, all while maximizing your ROI in System Center. Title: Optimizing System Center Operations Manager for cross-platform monitoring, regulatory auditing and advanced visualizations Learn how to optimize System Center Operations Manager for cross-platform devices and applications, regulatory auditing requirements, and how to create advance LOB, geographic and executive level dashboards in SharePoint. This session includes over 50 minutes of demos and presents customer examples of:
Presented By
Special Guests
May 07 Cross Platform auditing with ACSLast year we launched the Audit Collection Syslog Gateway™ which provides the ability to centrally collect SYSLOG events via the Audit Collection Service (ACS) within Operations Manager 2007 SP1. This enables organizations to centralize Windows, UNIX/LINUX and network security events within System Center for audit and reporting purposes. As an agent-less solution customers can simply deploy the Syslog Gateway, enable forwarding on target devices, applications or from an existing Syslog server and start to use ACS as a central cross-platform audit repository within the enterprise.
In a couple weeks an updated build for the Audit Collection Syslog Gateway, Service Pack 1, will be released that improves the core service and gateway logging with an improved installation wizard. The SP1 also introduces a health MP which includes security alerting rules for UNIX operating Systems, Cisco Firewalls and Routers plus an MP Template which enables users to create custom alerts and views for any Syslog event.
Below is a general overview on the Audit Collection Syslog Gateway architecture and features.
Audit Collection Syslog Gateway Overview · Provides SYSLOG event collection, alerting and reporting for UNIX/LINUX and network devices via ACS · Includes Secure Vantage Syslog Gateway Service, Generic Syslog Report and alerting Management Pack · Requires Operations Manager 2007 SP1 with ACS, and a Windows Server with Forwarder to act as Gateway
Common Syslog Sources · UNIX/Linux Operating Systems like AIX, BSD, HPUX, Mac OS X, RedHat, SuSE, Solaris, zOS and others · Network devices like Cisco Routers, Switches and Firewalls · Environmental devices and 3rd party applications like Citrix Application Gateways or Web Servers · Most hardware and applications running on a UNIX/Linux OS
Deployment Considerations · Must enable SYSLOG forwarding on endpoint (User Guide has instructions for Unix and Cisco devices) · Default SYSLOG collection is UDP on port 514, TCP is optional in most cases but must be configured · Single Gateway supports up to 200 devices or 1000 Events Per Second (EPS)
Syslog Gateway Reporting The Audit Collection Syslog Gateway includes one generic report that enables users to filter on any Syslog message pattern or all events. For example users could filter for all Cisco ASA events, all events with ‘root’ or from a specific device. Users can then save these filters as report subscriptions and quickly establish a standardized set of reports for auditing purposes.
Syslog Gateway Management Pack (included with upcoming SP1) The Audit Collection Syslog Gateway MP provides health and performance monitoring of the Gateway Service plus security alerting for the Syslog events. The security alerting includes canned rules and knowledge articles for UNIX/Linux operating systems security events like logon failures, root access and suspicious activities; alerting rules for Cisco routers and firewall IDS events, plus an MP Template that enables users to quickly create custom views and alert rules for any Syslog event pattern. Users can easily override existing rules and use the MP Template to implement custom alerting and security auditing within their SCOM environment.
Below is a sample of Syslog facilities and priority codes which can be used for alert filtering and reporting.
Useful Syslog Links and Resources · NIST: Guide to Computer Security Log Management o http://csrc.nist.gov/publications/nistpubs/800-92/SP800-92.pdf · IETF RFCs: 3164 The BSD syslog protocol & 3195 Reliable delivery of syslog o http://www.ietf.org/rfc/rfc3164.txt & http://www.ietf.org/rfc/rfc3195.txt · SANS Institute: The Ins and Outs of System Logging Using Syslog o http://www.sans.org/reading_room/whitepapers/logging/1168.php · Cisco: Identifying Incidents using Firewall and IOS Router Syslog Events o http://www.cisco.com/web/about/security/intelligence/identify-incidents-via-syslog.html
Looking towards SCOM R2 This year at MMS Microsoft announced ACS for Cross Platform, a post SCOM R2 feature, which enables partners to integrate non-Windows security events into the ACS collection stream. With this capability any cross platform log file source exposed via SCOM R2 could be integrated into ACS, allowing organizations to centralize all security auditing events into a single repository which can be alerted, reported and archived as needed. The feature enables parsing of the event messages to extract key attributes and strings for improved reporting and analytics. The diagram below illustrates the high-level concept of this upcoming feature; in general it’s the same architecture as our Syslog Gateway, except the event source is from the SCOM agent vs Syslog and the event transformation is optimized to enable more granular data mining.
For users planning to leverage the new cross platform capabilities of SCOM R2 you’ll soon have the ability to integrate security events from those devices and application into ACS natively and will be pleased to know we’re migrating our alerting and reporting functionality to leverage this new feature as well. Users wanting to leverage the new SCOM R2 feature should enroll in our TAP program or stay tuned for more details and announcements.
Users needing a solution today or who have agent-less requirements can use the Audit Collection Syslog Gateway, which provides a very cost effective option that is licensed per Gateway (not per device) that’s easy to deploy and simple to use. And remember, regardless of how you collect your security events, once they’re in ACS our entire suite of Security Auditing solutions can be used for alerting, archiving and data analysis.
If you need more than just security auditing we have two partners who provide great health and performance monitoring solutions for cross platform devices and applications: BridgeWays and JalaSoft. By combining the breadth of partner monitoring solutions with our security auditing features in ACS, users can standardize and simplify systems management, auditing and compliance within System Center which reduces the cost, complexity and overhead associated with managing your heterogeneous environment. May 04 MMS 2009 Secure Vantage Highlights - Part 1MMS 2009 was another big year for Secure Vantage Technologies Inc. This year we launched several product updates and new features including a VMM PRO pack and extended support for Cross Platform security auditing. It was great to see all our customers and partners at the event and hear all your positive feedback. For those who couldn’t make the show or are looking for more information, we’ve put our MMS 2009 highlights below. Big thanks to the community for their support with helping make this another successful event for Secure Vantage. We hope everyone liked the bags. J Read MMS Press Release: Secure Vantage Adds Unix, Linux, Cisco and Virtualization For Cost-Effective Enterprise Data Center Compliance and Auditing Solution Using System Center Secure Vantage MMS 2009 Highlights Product Showcase The demo environment we had at our booth and breakout session this year was something we worked on over four weeks in conjunction with several other ISVs. Built on VMM and SCOM R2, the virtual environment had Windows Server 2003 and 2008 systems and even a Linux RedHat server. We loaded all our current builds plus Savision LiveMaps, BridgeWays MPs for Apache and Oracle, JalaSoft MP for F5, Silect Software’s MP Studio and the new OpsLogix Ping MP. We even set up a Microsoft Office SharePoint Server to show a sample portal that has integrated SCOM and SCCM views for team sites with a central control list for tracking auditing activity that had KPIs (Key Performance Indicators) used to track various GRC auditing benchmarks. We’ll be posting some screenshots and videos of the showcase soon; just waiting for our demo boxes to return from the event. For those interested we already saw one recording posted online at http://www.mmsnews.info/video/securevantage-1 The list below summarizes the Secure Vantage solutions we demoed last week in the MMS expo hall that will be coming available for general download soon. Stay tuned for more solution announcements, updates and releases. · Audit Collection Admin, RC2 The Audit Collection Admin centralizes ACS administration, improves health monitoring and reduces the complexity associated with ACS management. This is a must-have for every ACS environment that helps ensure your audit infrastructure is healthy and available, reduces the complexity of managing multi-Collector environments and simplifies administrative tasks. · Audit Collection Syslog Gateway, SP1 The Audit Collection Syslog Gateway is an agent-less solution that enables users to forward Syslog events from any UNIX/Linux Server, network and firewall device, OS and any Syslog enabled device or application like Citrix Access Gateways to ACS for centralized collection, storage, reporting and alerting. The Syslog Gateway now includes an alerting MP with canned rules and knowledge articles for common UNIX/Linux security events and Cisco Firewall and Router IDS events. · Security Management PRO pack The PRO feature for our Security Management packs allows users to restore or revert a VM based on security audit violations like specific GPO changes or compromised systems. The PRO pack tip is available for customer testing and will eventually be incorporated into the Security Management packs. · Audit Collection Archiver, SP2 The Audit Collection Archiver has had some general improvements to the core service, plus we showcased the new user interface that is now supported both standalone and in the SCOM console while providing significantly more functionality and ease of use for users.
· Audit Collection Data Miner, Beta1 A new addition to the Security Auditing family of products, the Audit Collection Data Miner enables ad-hoc query analysis of both online and historical audit databases directly from the SCOM console. This enables users to quickly search both Windows and Cross Platform security event data without having to run a custom report or SQL query.
· Audit Collection Base Reporting, SP2 – Consolidated Win2003/2008 audit reporting Our ACS reports have been extremely optimized with new indexing and queries resulting in over 80% improvement in run-time. We’ve also worked very hard on providing consolidated Windows Server 2003 and 2008 audit reporting for customers with mixed environments. · GRC Portals for Microsoft Office SharePoint Server (MOSS) This year we demonstrated how customers can build GRC (Governance, Risk and Compliance) portals using Microsoft Office SharePoint Server and System Center. We showcased integrating dashboards and state views as well as how users can automate report delivery and review tracking, providing the organization KPIs on current compliance state and auditing objectives. This is a great demonstration of how any organization using MOSS can quickly implement an internal control list for workflow tracking with automated audit assessment and report delivery. Cool Announcements To Watch the MMS KeyNotes and other MS videos visit the virtual press room, http://www.microsoft.com/presspass/presskits/infrastructure/videoGallery.aspx 1) SCOM Visio Integration – Day 1 Keynote, about 1hr and 2 minutes in In the day one keynote by Bob Kelly, Lorenzo Rizzi with the SCOM product team demoed a new feature in SCOM R2 that enables users to integrate Visio diagrams with dynamic state and alert data from Operations Manager. While not nearly as feature rich as the Savision LiveMaps, this definitely got a good applause and is something many customers will take advantage of. 2) Compliance Management with Service Manager – Day2 Keynote, about 58 minutes in In the day 2 Keynote by Brad Anderson, Claire Harte with the Service Manager team presented how customers can automate compliance assessments, audit lifecycle and control enforcement using workflow in Service Manager that ties together data from SCOM, SCCM and Active Directory to enable organizations to better manage, mitigate and report on risks in the enterprise. This introduces the final layer in the System Center fabric for managing audit and compliance lifecycles for GRC related activities. This is a very exciting announcement, and you can expect we’ll be talking a lot more about this moving forward. 3) ACS for Cross Platform – ACS Breakout Session On Friday Maarten Goet, a SCOM MVP with Inovativ, presented the Audit Collection Services breakout session and demoed cool dashboards for ACS using Savision and Secure Vantage plus an extensive overview on Syslog auditing and the upcoming ACS for Cross Platform, a post R2 feature that enables partners like Secure Vantage to integrate event log sources from UNIX/Linux and cross platform applications natively into ACS for alerting, archiving and analysis. Now SCOM users will be able to audit from any Syslog device or CrossPlat source. We’ve been chipping away preparing for this one, so upgrade to SCOM R2 today and get ready. 4) System Center Central If you’re a System Center user, engineer or administrator then you gotta check out this new site. System Center Central is a combination of a bunch of community MVPs, bloggers and partners that have consolidated their sites into a central community portal. Keep watch as the content is growing daily and we’re working away on an ACS Wiki too. www.systemcentercentral.com
Cool Partner Solutions on Expo Floor I’m sure there were lots of great demos on the expo floor, but two really made an impression on me. 1) New Vista Gadget for Savision LiveMaps that provides small alert/state widget that expands to show specific LiveMaps view with full operator functions. Very slick, guys. 2) Nice password management feature from Lieberman Software that enables users to easily reset and apply random passwords for SCOM and SCCM service accounts. Let us know what you think; we get lots of requests for password management tools and these solutions look great.
Raffle Winners Every year we have cool booth swag and great raffles for attendees. This year was no exception where we offered the two prizes everyone has been asking for. Congratulations to all the winners or our MMS 2009 raffles! Booth Raffles · MMS 2010 Attendee Pass: Jeffrey Howell , already coined best MMS 2009 giveaway · Zune for your Tunes: Jeffrey Barlow and Ricky Moolraj · Gondola Ride with the Angels, lost the names but posted some pics in the MMS 2009 album Partner Raffles · Chris Angel Show Tickets: Shay Byrne · Microsoft Zune Player: Gordon McKenna · $100 Poker Chip: Derek Cullen MMS 2009 ISV Über Demo This year we decided to show our partners and customers how System Center Operations Manager R2 can be optimized with partner solutions to address cross platform monitoring, security and enhanced visualizations. We had about 40 folks in attendance and outside a few prep slides mostly did demos of the individual ISV solutions and how they can be wrapped together and presented in SharePoint. The session included over 50 minutes of demos, including: BridgeWays for Apache and Oracle, Savision LiveMaps for enhanced presentation layer and Secure Vantage Technologies for security auditing and compliance. Given the session feedback and content we decided to host a webcast for those who couldn’t attend. Stay tuned for more details and registration info. Download Session Deck: TS 40, ISV solutions for cross-platform monitoring, regulatory auditing and advanced visualizations
MMS 2009 Secure Vantage Highlights - Part IIMMS Bag, Partner Swag and Flyers This year we sponsored the MMS Attendee Bag to make sure everyone got something cool they could carry around with them after the event. Below is snapshot of the attendee bag and contents including our special edition flyer hosting the IT 24-7 robot and Cross Platform Penguin.
We also gave our partners a cool swag bag at our MMS Airlift with all the Secure Vantage accessories. At the booth we had some fun paddle balls that found many uses; mini DVDs with all our solution flyers plus the ACS Master Class Series and ACS Resource Kit, new ACS Whitepaper and even trial software for the Security Management packs.
Partner Swag Bag*
*Not all bags had a Secure Vantage mouse
ACS Whitepaper and Flyer Revamp
Download Flyers and Whitepaper · Audit Collection Base Reporting & Data Miner · Audit Collection Syslog Gateway · Security Management Solutions · ACS Whitepaper, MMS Pre-Release The Angels After three years we figured it was time to spotlight a major force in our presence at MMS and something that has seemed to revitalize the energy in the expo hall, the Secure Vantage Angels. These girls took the show by storm in 2007, promoting our brand to every attendee they saw and tripling the company’s booth activity. Smart, fun, energetic and beautiful the Angels have left a lasting impression on everyone they meet. While other ISVs have followed suit, which was widely seen this year, no one has captured the hearts and memories like the Angels have. Here’s a few looks back at past events. · MMS 2007 – Carley & Stephanie in San Diego · TechEd EMEA 2007 – Stephanie & Carley in Barcelona · MMS 2008 – Carley, Stephanie & Heather in Las Vegas · MMS 2009 – Stephanie & Shannon in Las Vegas Want to see the Angels in Berlin for TechEd EMEA 2009? Send your vote to angels@securevantage.com Secure Vantage Factoids MMS 2006 – 2009 This marked the fourth year Secure Vantage has sponsored the Microsoft Management Summit, so we wanted to share some facts and figures from our attendance to date.
Big thanks to all our partners, customers and the community for helping us have another great MMS. We look forward to sharing the solutions we showcased soon and seeing everyone again next year. Want one of those cool Attendee Bags and all the Swag? Be one of the first three people to send an email to sales@securevantage.com and we’ll ship you a bag filled with all the swag.
Bonus Question I took a helicopter ride down the Grand Canyon and over Vegas with a partner on Sunday before MMS kicked off. Name the Partner and Guys sitting in the chopper with me. First correct response gets a single Collector license for the Audit Collection Admin and Syslog Gateway. Thanks again guys, wicked cool ride! April 16 MMS 2009 with Secure VantageAre you ready to learn about the latest in Microsoft management technology?
The Microsoft Management Summit is the premier training event of the year where users and partners can gain a wealth of information on the Microsoft System Center suite of management products and ISV partner solutions.
This will be Secure Vantage’s fourth year sponsoring MMS and showcasing how easily System Center can be extended for security auditing and compliance. We'll be announcing several updates to our suite and showcasing a variety of technology that customers use today to support security and regulatory audit requirements. We’re also proud to be sponsoring CommNet again to provide security auditing for the event and hosting a great break out session for the community that you won't want to miss.
If you’re interested in learning more, scheduling some time with the team or have any questions let us know. For those who can’t make the show stay tuned for our May Newsletter and postings to our blog.
We look forward to seeing everyone in Vegas.
Cheers,
The Secure Vantage Team Secure Vantage Technologies Inc.
P.S. Congratulations to Kurt Peterson of Milford Michigan, the winner of our MMS 2009 Attendee Pass Raffle held on MyITForum. We hope you have a great event Kurt.
MMS 2009, Secure Vantage Highlights and Logistics
Booth Demo's and Discussions
CommNet Showcase This is the fourth year Secure Vantage solutions are being used to improve the security management, auditing and compliance of MMS and other Microsoft events worldwide. The CommNet environment hosts the infrastructure used to provide services to attendees, sponsors and presenters which is running on System Center Operations Manager R2 to manage the environment. This year you’ll find our Security Management packs and Auditing solutions for ACS on display and in use in the CommNet lounge. ISV Über Demo ISV solutions for cross-platform monitoring, regulatory auditing and advanced visualizations Session TS40, Wednesday 10:15am in San Paolo Room Learn how to optimize System Center Operations Manager for cross-platform devices and applications, regulatory auditing requirements, plus how to create advance LOB, geographic and executive level dashboards in SharePoint. This session includes four demos and presents a customer example of extending Operations Manager for Oracle and VMWare monitoring using BridgeWays, supporting SOX and PCI audit requirements using Secure Vantage Technologies, and building intelligent views across these solutions using Savision LiveMaps.
This session includes 50 minutes of demo's and covers 10 use cases for optimizing System Center with partner solutions. Whether your a System Center user, partner or engineer in the field this session is just for you. Don't miss this exciting chance to see first hand how all these partner solutions extend System Center and work even better together. April 10 Secure Vantage SCOM R2 Supportability UpdateWith the recent release of SCOM R2 RC we’ve had a lot of inquiries on which solutions are supported today and will be soon. For those interested we plan on having full support for all solutions in-line with the upcoming R2 release, below is a summary of current testing on SCOM R2 but please be aware we are not providing official support outside of our early adopters program until R2 is generally available. SCOM R2 supportability status as of 4/10/09 · Security Management packs – Tested with no reported issues · Audit Collection Admin RC – Admin view does not display, requires client update · Audit Collection Archiver – Tested with no reported issues, SQL Server 2005 only · Audit Collection Base Reporting – Tested with no reported issues, SQL Server 2005 only · Audit Collection Syslog Gateway – Tested with no reported issues, Windows Server 2003 only On a related note we are also working on full SQL 2008 support across the suite and plan to release several updates moving through the year. Stay tuned for more details on SCOM R2 and SQL 2008 support or contact us to learn more about our early adopter program. March 20 MMS 2009 Attendee Pass RaffleDo you need an attendee pass for MMS 2009?
We’ve had a lot of requests and with only one pass left we figured it was a good time to do another community raffle. This is open to anyone who registers online and provides the winner one full attendee pass to the Microsoft Management Summit 2009 in Las Vegas Nevada held April 27th through May 1st. This could save you or your company over $1000 on the System Center training event of the year. Don’t miss this great opportunity and register online now for your chance to win! http://www.myitforum.com/contest/swag/MMS2009.asp Entrants: Please note this raffle does not include travel, lodging or any other costs associated with MMS. All costs outside the attendee pass are sole responsibility of the entrant. Attendees stay tuned for more details on MMS 2009 from Secure Vantage. March 13 ACS Optimization with Secure VantageWe’ve recently had some inquiries requesting a high-level overview of what Secure Vantage Technologies does from a technology perspective to optimize the Audit Collection Service (ACS) for enterprise auditing requirements. Below is a diagram and link to short video that walks through the basic concepts of how Secure Vantage's Security Auditing solutions enable you to fully leverage ACS for cross platform security event collection, analysis, alerting, archiving, reporting and more. ACS Optimization with Secure Vantage: http://www.securevantage.com/docs/ACS%20Training/ACSOptimizationWithSecureVantage.zip ACS Optimization in a Nutshell - Video Summary
Secure Vantage Technologies helps optimize the Audit Collection Service to better enable organizations to address the needs of today’s enterprise and regulatory requirements.
The first way Secure Vantage enables user is with the ACS Master Class Series, over 6 hours of technical training covering everything from design and planning to optimization and advanced configurations. This is complemented by the ACS Resource Kit which includes a wealth of utilities, documents and resources for ACS administrators and engineers. Both of these are free community downloads.
Looking at the ACS environment we now turn to the Audit Collection Admin which provides a robust management, health monitoring and user interface. This solution ensures your audit infrastructure is running efficiently and that users can easily administer the entire environment.
Knowing the ACS infrastructure is healthy we can now focus on using the collected security data. This is where our Base Reporting and Data Miner solutions provide tremendous value with a rich reporting library for Windows Server 2003 and 2008 plus ad-hoc investigation tools.
Most users typically now have a need to save the collected security events for corporate or regulatory requirements in a cost effective way for use in potential investigations or long-term reporting and analysis. This is where the Audit Collection Archiver is used to offline the ACS event partitions into compression files and provides a near-online historical repository which enables optimized data mining, forensics and multi-Collector reporting capabilities.
For users who have unix, mainframe or network devices our Audit Collection Syslog Gateway provides a very cost effective solution that enables centralized collection, reporting and archiving of security events. This Gateway comes with a generic report that can be filtered on any syslog event pattern plus a Management Pack for security operations with canned alerts for Unix OS and Cisco events.
Finally for organizations looking to have greater visibility into their Active Directory and Group Policy infrastructure our Security Management packs provide real-time alerting on over 400 auditing controls, advanced knowledge articles, security operational views and over 20 auditing wizards.
Together, the Secure Vantage suite helps organizations truly optimize ACS for today’s enterprise datacenter auditing and regulatory needs. March 11 Events in MarchThis month we’ll be presenting two sessions on the Audit Collection Service (ACS). One session will be at the Microsoft Higher Education Summit and the other is a webcast for Microsoft field and partners. This is a great chance for System Center customers and partners to learn more about the Audit Collection Service, how it can help with security auditing and see live-demo’s of an ‘optimized’ ACS infrastructure. If you’re attending the Hi-Ed summit, a System Center partner or Microsoft field these sessions are for you. Microsoft Higher Education Summit, March 30th - April 1st, Microsoft Redmond Campus Connect and collaborate with your higher education IT professional peers on deep technical topics covering evaluation, deployment, and support of Microsoft technologies. This event is like a mini TechEd targeted specifically for professionals working with Microsoft technologies in the education sector. Summit Agenda: http://windows-hied.org/wiki/index.php5?title=Agenda_2009 Register Online: http://www.ustechsregister.com/educationevents Session: Audit Collection Service with Operations Manager Session Logistics: Tuesday, March 31st, Bldg 37 10:15-11:15am PST Description: Learn how your educational organization can maximize their investment in System Center to support security and compliance audit logging requirements using System Center Operations Manager and the Audit Collection Service (ACS). This is a great opportunity to see firsthand how you can centralize security event log collection and reporting across the enterprise. In one hour, you’ll learn everything you need to know about what ACS is, how it can help your organization, and how to optimize ACS to support educational environment audit requirements. Microsoft System Center ISV Showcase, March 25th, 10am PST, Web Seminar EventID 263360 Registration: Microsoft Partner Learning Center or Contact Us Session: Enterprise Auditing with the Audit Collection Service (ACS) Session Logistics: Wednesday, March 25th, 10am PST Description: Learn how your customers can maximize their investment in System Center to support security and compliance audit logging requirements using System Center Operations Manager and the Audit Collection Service (ACS). This is a great opportunity to learn how you can optimize ACS to support enterprise auditing requirements such as security alerting, data archiving, historical reporting, and syslog event collection using Secure Vantage Technologies’ Security Auditing solutions for ACS. In one hour, you’ll learn everything you need to position ACS as a competitive enterprise auditing solution and System Center as a strategic asset for corporate governance, risk and compliance initiatives. March 04 Security Management packs SP1 availableToday Secure Vantage released Service Pack 1 of the Security Management packs for System Center Operations Manager for general download. This release provides several significant updates to the December release including more security alerting and operational views, full installation support on Windows Server 2008, new MP Templates and several improvements to our licensing service. The below information summarizes the release highlights and some links for more information. Read Press Release Secure Vantage Technologies releases SP1 to their Security Management packs for System Center Operations Manager
Request Download for your Security Management pack upgrade or trial Release 3.0.6630 Change Log · Full installation support for Windows Server 2008 · Package tested on Windows Server 2003/2008, 32/64bit and Clustered RMS. · Addition of Windows Server 2008 discovery rules · Addition of 74 alerting rules for Windows Server 2008 · Updated Multiple Logon Failures rule to enable override on Count and Time thresholds · Consolidation of alert views and OS folders to ease console navigation · Introduction of root computer group used as single container for MPs · Update of central License Service managed via SDK/Connector · Addition of License Service Manager client UI · License File use deprecated in favor of License Keys (migration of License Keys from physical file to license code stored in registry) · New MP Templates for File/Folder auditing, Group Policy and more User Upgrade Notes · Only supported for environments running 3.0.6200.0 or higher · Upgrade process is automated and converts existing license file and service · Trial installations cannot be upgraded, solutions must be uninstalled/reinstalled · Does not impact or modify any Security Auditing components for ACS Security Management SP1 Screenshot Samples Sample 1: Revised View Structure Sample 2: Updated Group Policy Views Sample 3: New Security MP Templates Sample 4: Windows Server 2008 KB Sample February 24 New Savision Security Dashboard Accelerator AvailableWe are pleased to announce general availability of the Secure Vantage Security Dashboard Accelerator for Savision Live Maps 3.0. This new accelerator enables users to quickly deploy canned dashboard packs for the Secure Vantage Security Management packs to gain high-level visibility into security operations, auditing and compliance state within your System Center Operations Manager environment. Security Dashboard Accelerator Online The Security Dashboard Accelerator is a free download for Secure Vantage customers and partners. It includes a dashboard pack xml file which imports into Savision Live Maps Authoring console (image below on left), a user guide plus Secure Vantage icons and images to create your own custom dashboards as shown below on right. With the launch of this new accelerator we also now bundle Live Maps with our Security Management package. This ensures every user can benefit from this accelerator and has the ability to add more intelligent presentation layers on top of our security auditing and compliance solutions for System Center Operations Manager. To learn more about Savision and how Live Maps can help you visit their Homepage or Team Blog. Savision Bundling & Accelerator FAQ · If I already own both products can I just download the accelerator? Yes, contact sales · If I already own the Security MPs can I purchase a Live Maps upgrade directly from Secure Vantage? Yes, contact sales for upgrade options · How many Live Maps ‘View Licenses’ does the Accelerator use? Five (5), 4 for core dynamic lists and 1 for dashboard that consolidates lists. · How do we get the ‘Security Compliance’ dashboard sample shown above? This is a sample built using the Security Dashboard Accelerator · Can we link specific SCOM Views and Reports? Yes, you can link any URL or Web Console view February 13 ACS Archiving, Storage and ReportingWhen planning an audit environment using the Audit Collection Service (ACS) provided within System Center Operations Manager (SCOM), numerous needs for data collection, retention and reporting arise which extend beyond the solution’s native capabilities. In this blog, we take a look at new configuration options available when using our Security Auditing solutions for ACS. Specifically, we’ll examine how ACS can be optimized to support enterprise reporting and retention requirements using the Audit Collection Archiver™. Online Reporting Considerations First we need to understand how ACS provides online reporting given its core design. The ACS online audit database is designed for optimal insertion and online storage efficiency. This is achieved by processing all events through a normalization schema (EventSchema.xml) that parses through the event attributes and maps the values to an online data model. This model includes partitions of data (by default 1 partition per 24hrs) with individual tables that store the event header and detailed attributes from the event description. To support reporting, the audit database includes 3 core views: dvEventHeader, dvAll5, and dvAll. These views combine all existing partitions in an ACS database, allowing the information to be accessed for reporting and data mining. The views include data from the active partition that has events being inserted along with data from all other partitions, indexed and non-indexed (see KB 949969, which resolves the impact of non-indexed partitions being improperly groomed but doesn’t actually re-index the partitions). The views include all event strings, not only the strings used in the report. Additionally, every partition in the view creates another partitioned table in the query, eventually reaching the SQL 2005 limit of 256 tables (see KB 954958). So while these views provide access into the ACS data, they are not optimized for data analysis. All this data needs to be indexed for optimal query and report performance. Unfortunately, you always have one partition with active events being inserted and possibly 1-2 partitions waiting to be indexed. This means regardless of how much data you have, the 2-3 most recent partitions are not staged for data mining and will always impact performance of queries and reports. Now let’s look at an example. Say you retain 30 days of information and are running an investigation for activity in the last 5 days. Any query you run using the default views in ACS will query the entire ACS database, not just the partitions pertinent to the query. Additionally, the configuration, resources and indexing status of the ACS audit database can further hinder performance. To put this in perspective, let’s say you collect 5GB of events per day, which is roughly 3.5 million records. This means by default your report runs a query against 150 gigs and 90 million rows, of which only 1/10 are likely un-indexed (as opposed to just the 25GB and 15 million rows of data that actually matter). That’s a huge difference and a significant delta for optimal data mining. Although you can customize your own queries, you still run into fundamental challenges given the active event insertion, data volume and indexing status. In the end, reporting via the online database is a question of data insertion rate and volume, database health and raw horsepower. Make sure you review the ACS Master Class Series, Session 2 (ACS Design & Planning) for common best practices and planning considerations. So now the questions we tend to ask ourselves are: Is the online audit database the best place to run reports? How much data can I keep online without impacting ACS performance? How can I store and use this data beyond the default retention period of 14 days? And so on…….. Online vs. Near-Online vs. Offline Because the online system has the active event insertion data, this repository is the best location for short-term audit needs under 72 hours but is not well suited for historical reporting or offline storage. As we now know, out-of-box ACS is only intended for online event collection and really only provides the core architecture for collecting Windows security logs into a central repository. What you do with the data and how it’s managed from there will vary depending on how you plan and optimize that architecture. Here’s where Secure Vantage comes in. The Audit Collection Archiver provides the ability to save event partitions offline in compressed files and also set up a historical audit reporting database. With these two options, we can now plan and optimize our audit environment to support online, near-online and offline auditing needs. Users will also feel safe knowing the Archiver is the only ACS solution available that’s Microsoft Certified for SQL Server 2005. Typically we see organizations using the Archiver for one of these three reasons: 1. Their online database supports reporting and subscriptions, but the data must also be archived. 2. Their reporting requirements exceed online database capabilities and require historical reporting. 3. They wish to consolidate reporting across multiple collectors. In a standard ACS environment, we usually see some form of the below approach when using the Archiver to manage the ACS event data lifecycle.
You can significantly optimize your audit infrastructure by using the Archiver to extend the native storage, retention and reporting capabilities of ACS to support the preceding three scenarios and more. The diagram below helps illustrates these basic design principles and how they relate to managing the ACS security log data.
This capability enables organizations to implement a far more effective ACS archiving, retention and grooming policy that supports your unique business needs. While design always takes into consideration factors such as performance, scalability, available resources, and disaster recovery, the Archiver provides a strong foundation for a robust audit infrastructure leveraging ACS as the backbone. The diagram below illustrates one example of how this technology can support the online, near-online and offline data requirements for an enterprise environment more effectively.
Storage Requirements With the ability to store data longer than the online database and set up a historical repository comes the need to plan for storing all this data. In general, the historical database has relatively the same overhead as an online database but will typically be much larger as more information is maintained for reporting. Archives, however, are only a fraction of the online data size and can be stored to any form of media. So given the previous scenario where the ACS Collector creates 5GB of security event data per day, you keep the default 14 days online, want 90 days of data available for reporting, and need to keep all data 13 months. The table below would summarize the components and general storage estimates we’re working with.
To assist customers in planning for these new storage needs, we’ve extended the ACS Disk & Data Storage Planning Calculator released on System Center Forum to include an additional worksheet with the formulas and variables to compute these storage requirements. You can find this worksheet in the ACS Resource Kit, a free community download. Optimized Historical Reporting So we have the option to set up a Historical Audit database, but how does this really help improve reporting, knowing how the online database functions? In the upcoming SP2 of the Audit Collection Archiver, you can set up a custom historical database with optimized indexing, data aggregation and flexible grooming to support your specific audit requirements. Additionally, you’ll get advanced views that only query the partitions with pertinent data and the strings applicable to the report, further improving report run-time. Another nice feature is the option to run the reports against the online or historical database along with full date/time and localization support. That means you can configure reports for the UK date/time format to show data as Day/Month/Year as opposed to the US default of Month/Day/Year (see our team blog Modifying the DateTime Format on ACS Reports for more information). We also resolved the data mapping issue between Windows 2003 and Windows 2008 security events by providing consolidated reporting and attribute mapping (i.e. ACS writes the Primary User info of a security event from Win2003 and Win2008 differently, resulting in discrepancies when comparing security data across operating systems; we remap this data in our reports for optimized forensics and investigations). The diagram below illustrates the ACS historical database design and shows how different report scenarios might query the historical audit database. In Conclusion If you’re using ACS and need historical reporting and archiving, get a solution that's proven and easily scales to your organization’s needs. Check out the Audit Collection Archiver and the rest of our Security Auditing solutions for ACS. January 30 ACS Access HardeningWe posted another ACS Master Class Series session today, ACS Access Hardening. For those of you looking to lockdown or harden the Audit Collection Service (ACS) this is a must see. The rerecording is presented by ACS guru and SCOM expert Graham Davies a Sr. Engineer with AKCSL based in the UK. Graham’s worked on some very large and ‘secure’ ACS environments, is a frequent contributor on Microsoft technet forums and presents a great session on how to harden ACS. Download Video: ACS Access Hardening In roughly 15 minutes this session walks through general ACS vulnerabilities and hardening options plus two demo’s covering Forwarder hardening and SCOM Reporting lockdown. The information below summarizes the content and information covered in this session. 1. Forwarder Service can be stopped or reconfigured to undesired state 2. Collector Service can be stopped, noise filters manipulated 3. Collector to DB communications is unencrypted 4. Audit Database is governed via SQL security 5. Reporting via OpsMgr opens all reports to all users using console 6. Archived files should be secured and monitored for any miss use
Session Demo’s · Demo 1: Locking down the ACS Forwarder service · Demo 2: Locking down ACS report access in the SCOM console We’ve had a lot of customers and partners ask about locking down ACS reports in SCOM and the second demo shows you exactly how to do it. The demo walks through how to create a new SCOM Role and modify Reporting Access Rights associated with Roles. This enables you to remove the default user access in SCOM reporting and provide a specific Role to assign users access to ACS audit reporting. Please note Demo 2 is based on guidance and resources available in the Security Reporting in Operations Manager 2007 guide posted on System Center Forum. Stay tuned as we continue posting the rest of the ACS Master Class Series online and make sure you check out the Secure Vantage Technical Tuesdays for our 2009 training sessions. January 27 Moving into 2009So it’s time to start cranking the wheels and blogging for 2009, you’ll see lots of updates over the next few months so keep watch. Moving into the new year we thought it would be a great time to announce some important updates and continued improvements in our Security Management and Auditing suite for System Center Operations Manager. Below are three key things all our customers and partners should be aware of. Stay tuned as we have lots to share this year. J
Virtualization Licensing Program
This year we’re updating our licensing models to incorporate the growing tool set and bundling options customers have been asking for including our new Virtualization Licensing Program. Under this new offering customers save 60% on retail pricing for licenses running on virtual vs physical systems. This enables organizations planning and leveraging virtualization technology the opportunity to further reduce total cost of ownership. If you’re an existing customer or partner and interested in learning more about our Virtualization Licensing Program please contact us.
Windows Server 2008 Support
As many of our customers and partners know we’ve put a tremendous amount of effort over the past year into new knowledge resources and optimizing our solution packages. We continue making those investments and have several important releases coming out over the next few months. These updates will address known issues, simplify deployments and upgrades, improve internationalization support plus introduce installation and auditing capabilities for Windows Server 2008 across the suite. For more details on upcoming solution releases watch the team blog or contact us.
Secure Vantage Technical Tuesdays
Last year the ACS Master Class Series was a huge success, this year we continue the online training offerings and will be hosting technical webcasts the first Tuesday of every month starting February 3rd. This years online training will focus on planning, deploying, managing and optimizing Secure Vantage solutions for System Center. Customers and partners can register online for the upcoming series to watch them live or on-demand at http://www.securevantage.com/Support/TechTuesdays.aspx. December 19 ACS Resource Kit v1.1We’ve released an update to the ACS Resource Kit for the community. The ACS Resource Kit now includes a revised version of the ACS Disk Planning Calculator originally posted on System Center Forum, new database utilities for ad-hoc queries and advanced grooming, plus the ACS Visio Stencils previously posted on our blog. For more information and to download the latest version of the ACS Resource Kit please visit http://www.securevantage.com/Products/ACSResourceKit.aspx ACS Resource Kit v1.1, Contents 1. ACS Administrators Quick Reference – ACS newbie cheat sheet of common commands and configurations 2. ACS Database and Disk Planning Calculator – preplan online, offline and archive storage needs plus disk requirements for the online audit database 3. ACS Database Event Analysis a. ACS Summary Stats - XLS you can connect to ACS DB for event load analysis b. Query Active Partition for Event Counts c. Query Active Partition for Specific Events d. Windows Security Auditing Reference List – List of windows security events, settings and common configuration items for Windows XP, Vista, Windows Server 2003 & 2008 4. ACS Database Utilities a. Groom Specific Events from Audit Historical Database 5. ACS Noise Filtering a. ACS Noise Filter Guide b. My Generic Filter – Sample noise filter c. Filter Setup Kit – Auto apply generic filter sets after ACS installation 6. ACS Security Event Creation Testing – Scripts to create events for over 50 audit scenarios 7. ACS Visio Stencils – Microsoft Office Visio Stencils of common ACS components December 17 ACS Health ChecksWe've had quite a few partners and customers recently ask about how to do routine health checks for System Center Operations Manager environments using the Audit Collection Service (ACS). We wanted to share the general checks we use for ACS and also discuss how the Audit Collection Admin can centralize the presentation of this data and automate these routine tasks to help you maintain a more reliable audit infrastructure.
So how do we run an ACS health check? Below are common tasks one can run in an ACS environment to confirm the audit infrastructure availability, performance and health. Please note this list only outlines a health check and does not include step-by-step instructions or problem resolution guidance. For more information on planning, troubleshooting or optimizing an ACS environment please refer to the ACS Master Class Series.
Review ACS Configuration The primary objective when reviewing an ACS configuration is looking for potential hardware bottlenecks, design limitations and opportunities to improve the audit infrastructure.
Check ACS Collector/s Health
Reviewing an ACS Collector helps confirm active event collection plus general audit infrastructure health, availability and performance.
· Check Application and Operations Manager logs for Warning/Critical ACS related events
· Run 'AdtAdmin -stats' to review all active forwarders and load
o Note: Using the '-listforwarders' switch shows all Forwarders ever connected.
o Run 'AdtAdmin -stats -forwarderid <sid>' to investigate specific Forwarders
· Review ACS performance counters for utilization and statistics
o KPI: Database Queue and Backoff Threshold
Check Audit Database/s Server Health The Audit database is the core of ACS and a common source of most performance bottlenecks. It is important to ensure SQL is properly configured and supporting the event insertion load.
Check Audit Database/s Partition Health In addition to a healthy audit database the ACS audit partitions must also be reviewed to confirm they are being indexed, groomed and managed according to system configuration. This information can also be used for capacity and storage planning. · Confirm # of partitions online matches the configured value · Review partition size and row counts looking for trends or anomalies · Review partition retention, grooming schedule, time zone and offset · Confirm Indexing is occurring on partitions o Verify correct number of indexes on each partition table · Confirm grooming is occurring as scheduled, check for KB 949969 · Confirm view 'dvAll5' view is being built properly and is populated with data
Check Audit Database/s Archives Confirming successful audit database archiving validates data retention and usability.
Check Audit Reporting Access and Subscriptions Checking report access, run time performance and subscriptions helps confirm end users are able to access reports and automate a standardized reporting process.
Check Forwarder/s Health
ACS Forwarders can be reviewed or investigated as needed.
· Check OpsMgr ACS State Forwarder View for Health (checks ACS service is running)
o Check for any disconnected Forwarders
· Review Install base of forwarders against OpsMgr agents
Noise Filter Tuning ACS Noise Filtering provides a method to streamline event collection and improve data quality. Filtering policies should be reviewed on periodic basis to adjust for changes in audit policy, number of forwarders and environment.
Given the above ACS health checks, now the results can be used to improve the auditing environment performance, availability and general capacity planning. Outside of potential topology and hardware restraints typically the most common opportunities to improve ACS performance is via Event Noise Filtering and Database Optimization.
For folks who want to find most of the above information in a single location the Audit Collection Admin provides a centralized graphical user interface that allows administrators and engineers to quickly get the information they need to plan, manage and tune the ACS auditing environment from within the Operations Manager console. In addition the Admin provides extended health monitoring of ACS Collectors with detailed knowledge guidance for administrators.
A couple of other nice features for users include the ability to sort the detailed statistics from Forwarders and Database Partitions to identify high/low patterns or anomalies plus the option to copy-and-paste that data into Excel spreadsheets for additional planning and analysis. Whether you’ve been using ACS for awhile or just getting started this solution will simplify managing your ACS audit infrastructure and routine health checks. December 09 Security Management pack updateWe’ve released 2 significant updates for the Security Management packs for System Center Operations Manager (SCOM) 2007. New Reports for Security Management The first update is extended security reporting, including a Resultant Set of Policy (RSoP) and Group Policy Audit Reports plus SMB security event reports intended for System Center Essential (SCE) environments and customers unable to leverage the Audit Collection Service (ACS). Now customers can report on Group Policy discovery and change data plus implement light security event reporting without ACS. Security Management Report List · Group Policy o Resultant Set of Policy Report o Group Policy Change Audit and Impact Analysis · Small Business Reporting o Account Management o Audit Integrity o Domain Policy Changes Detail o Domain Trust Changes o Group Member Changes o Policy Changes o User Accounts Added Deleted o User Accounts Enabled Disabled o User Accounts Password Resets
Extended Alerting & Knowledge for Security Management
The second update is for our Windows Security Auditor MP which introduces more rules and knowledge content.
Management Pack: Windows Security Auditor Current Version: 3.0.6600.0 (Last Version: 3.0.6500.0) List of Changes · Added Multiple Logon Failures rule for 5 failed logons within 1 minute by same user on same machine · Extended rule set to include all Group Change event scenario’s o (ie Local, Global, Universal, Security & Distribution) · Added rules for Terminal Service session disconnects · Enriched Knowledge Articles with Security View hyperlinks
If you’re a current customer and interested in either of the above updates please contact us. November 13 Integrating Forefront Client Security with Configuration ManagerToday Secure Vantage will be presenting in the System Center Virtual User Group and demonstrating how to integrate Forefront Client Security (FCS) with System Center Configuration Manager (SCCM). You can register for the user group or download the recording on www.systemcenterforum.org
This session is based on a solutions accelerator posted earlier this year on CodePlex. One of these resources is now publically available for download from Microsoft, Deploying FCS definition updates with a shared System Center Configuration Manager WSUS infrastructure.
This document provides step-by-step guidance for maintaining FCS Anti-Virus and Malware signature updates leveraging your existing SCCM WSUS/SUP infrastructure. The diagram below highlights an overview of how these solutions work together in a shared WSUS environment.
For officially supported configurations on this integration please refer to Microsoft KB 9458491: Supported configurations for using WSUS to distribute Forefront Client Security Definition updates within SCCM 2007
The FCS team has also posted two related blogs on "Deploying FCS with SCCM 2007", download Step-by-Step or Video Guide
Why are we blogging about Forefront and Configuration Manager?
Well we wrote the guide for the Microsoft community (kudos to Kevin Colby) and secondly security management and GRC initiatives take more than just using Operations Manager and the Audit Collection Service. It's the combination of both System Center and Forefront technologies that enable customers to deal with today's security and regulatory challenges. We're glad we got to help bring this resource to the community and continue assisting customers fully leverage their investments in System Center and Forefront for GRC related activities.
To further help customers leverage both FCS and SCCM together we bundled the above resources with a DCM Configuration Pack for FCS. You can download the 'Integrating FCS with SCCM Toolkit' from the Secure Vantage website at www.securevantage.com/docs/IntegratingFCSwithSCCMtoolkit.zip
Please send any comments, suggestions or requests to improve this toolkit to support@securevantage.com |
|
|