Support
 
Support Get Quote
 
 
 
 

FES enhances security posture, opts for EventLog Analyzer over Splunk

About FES

FES, a non-profit foundation, dedicates itself to assisting communities and non-profit organizations, enabling them to concentrate on their core missions. With a nearly three-decade history, FES has been addressing the requirements of entities serving their communities, including hospitals, schools, and other non-profits. Filament (Filament Essential Services) operates as an affiliate of FES, with a rich history of assisting other non-profits.

FES established the Filament team and a range of services under their purview, with the aim of addressing the time-consuming challenges and talent shortages commonly encountered by non-profit organizations. The foundation supports organizations by establishing a professional presence, promoting their causes, enhancing IT security, and setting up networks or websites.

Company

FES

Industry

Non-profit

Location

United States

Main challenges faced by FES before EventLog Analyzer

FES recognized the imperative need for a robust log management solution to meet the stringent insurance requirements (NIST SP 800-53 Rev 5). The primary objective was not only compliance but also the enhancement of overall cybersecurity measures.

  • Insights into logging One of the main challenges faced by the organization revolved around gaining actionable insights from scattered logs hosted across various platforms. This decentralized approach not only hindered efficient threat detection but also posed challenges during compliance audits.
  • Splunk consideration While considering Splunk as an alternative, the organization encountered a bottleneck in terms of time constraints for deploying Splunk's heavy forwarder. This led to a reevaluation of options, ultimately steering towards EventLog Analyzer.

FES security needs met

Brett Lechner, a senior network engineer at FES, mentioned that the organization faced threats like denial of service attacks, phishing, and brute force attempts due to the public exposure of services. With the help of EventLog Analyzer's real-time alerts, they were able to identify and respond to security threats promptly.

He also mentioned that the built-in reports helped him gather information, thereby significantly reducing manual efforts, expediting the audit process, and ensuring compliance with industry standards.

“There's just a lot of pre-built alerts, rules, and reporting [in EventLog Analyzer] that saves a lot of time that we could have done manually. Before, we would have had to go through and research the event ID with the Windows event ID, and which alert that correlates to. And then just manually create all of that.”

Brett Lechner, Sr. Network Engineer, FES

Impact

According to Lechner, the main reason behind choosing EventLog Analyzer was due to its user-friendly deployment compared to Splunk. The solution allowed the consolidation of logs, providing more meaningful information.

Post-implementation, the organization experienced a remarkable reduction in the time taken to detect security threats. Within a week, Event Log Analyzer showcased its effectiveness in providing timely threat intelligence.

He also mentioned that he would highly recommend ManageEngine's onboarding services, and appreciated the team's willingness to share how the product works behind the scenes and get into its technical details. This helped FES have a better idea of how to tailor the alerts feature.

About custom onboarding

Custom onboarding is a ManageEngine service that provides solution implementation to clients upon request. This service includes installation and customized configuration of ManageEngine solutions. It enables clients to seamlessly begin work without worrying about the complexities of installation, deployment, and product use. Every client environment is unique and requires additional support beyond the basic installation and standard features. With custom onboarding, clients have the option to engage a team of product experts to manage the installation, implementation, customization, and training based on the business needs.

About EventLog Analyzer

EventLog Analyzer is a web-based, real-time log monitoring and compliance management solution for SIEM that improves network security and helps you comply with IT auditing requirements. Using an agentless architecture, EventLog Analyzer can collect, analyze, search, report on, and archive logs received from systems (Windows, Linux, and Unix), network devices (routers, switches, firewalls, and IDSs and IPSs), and applications (Oracle, SQL, and Apache). It provides important insights into user activities, policy violations, network anomalies, system downtime, and internal threats. It can be used by network administrators and IT managers to perform audits for regulations such as SOX, HIPAA, PCI DSS, and the GLBA.

Help us help others like you. Spread the word to the community as to how ADSolutions helped you and your business.

Thank you for your interest

Our product expert will contact you shortly.

Schedule a personalized demo with
our product expert.

  •  
  •  
  • By clicking 'GET A FREE DEMO' you agree to processing of personal data according to the Privacy Policy.

Thank you

Thank you for sharing your comments.

×

Share your story

A Single Pane of Glass for Comprehensive Log Management