SlideShare uma empresa Scribd logo
1 de 16
Have you planned your
                                         replacement for Cisco MARS?


© 2013, SolarWinds Worldwide, LLC. All rights reserved.

                                                          1
Agenda

1. Why should you find a replacement now?
2. What to look for in a replacement tool?
3. Why SolarWinds could be the right alternative
        a.     Deployment
        b.     Event Correlation
        c.     Power of Search
        d.     Compliance Reporting
        e.     Incident Response
        f.     Device Support
4. Additional Security Recommendations




CISCO MARS REPLACEMENT- SOLARWINDS LEM
                                         2
Why should find a replacement now?

»       What’s up with Cisco MARS?

       Cisco has decided it is right time for
        the hardware to not be sold in the
        market and it has been scrapped for
        new purchases                            Do you have a plan B?
       Cisco no longer sells Cisco Security     We have one for you…
        Monitoring, Analysis and Response
                                                 Check how SolarWinds Log and
        System (MARS)                            Event Manager (LEM) can help?
       Read the End-of-Life Notice to learn
        more




    CISCO MARS REPLACEMENT- SOLARWINDS LEM
                                             3
What to look for in a replacement tool?

»      Best-in-class SIEM technology provides:
       All-in-one affordable log and event analysis
       Active responses to react to real-time threats while complying with
        regulatory policies

»       Also a SIEM tool that has in-memory analytics that can capture, correlate
        and respond to network attacks and insider abuse at network speed.




CISCO MARS REPLACEMENT- SOLARWINDS LEM
                                          4
Why SolarWinds could be your alternative

Let us consider the top 6 decisive factors:
   1. Deployment
   2. Event-Correlation functionality
   3. Power of Search
   4. Compliance Reporting
   5. Incident Response
   6. Device Support

»       See how SolarWinds Log and Event Manager (LEM) compares to Cisco
        MARS on all the above parameters.




CISCO MARS REPLACEMENT- SOLARWINDS LEM
                                         5
Deployment

» Cisco MARS                                 » SolarWinds LEM
    It is a hardware appliance which           Its a virtual appliance which
     requires physical setup and                 downloads and deploys in just
     network connections to become               under an hour.
     fully operational.

    It is not a standalone solution,           LEM is all equipped own its
     but part of Cisco Security                  own and needs no supporting
     Management Suite which needs                and add-on devices or modules
     the support of Cisco Security               to deliver its full service.
     Manager (CSM) to deliver the
     full extent of service.




CISCO MARS REPLACEMENT- SOLARWINDS LEM
                                         6
Event Correlation

» Cisco MARS                                   » SolarWinds LEM
       It comes with the complexity of           As a standalone product, uses
        defining      and     building             its         multi-dimensional
        correlation rules to handle                correlation engine to detect
        multiple device and multiple               behavioral anomalies in real-
        events                                     time.
       Relies on Cisco CSM to perform            It also employs a simple and
        event correlation                          easy-to-use rule builder with
                                                   familiar drag and drop
                                                   interface, icon-based tool
                                                   panel and graphical object
                                                   selection panel.

  LEM also comes with 700+ pre-built correlation rules that cover critical network
  infrastructure, change management and network security functions.
CISCO MARS REPLACEMENT- SOLARWINDS LEM
                                           7
Event Correlation (Contd…)

»       SolarWinds LEM can:
       Correlate time-based and transaction-
        based events
       Send notifications and trigger actions
        based on event correlation that
        happens in-memory
       Perform multiple event correlation
       Ability to set independent thresholds
        for activity per event, or group of
        events
       Leverage non-linear event correlation
       Access to field-level data for event     LEM’s Correlation Rule Builder Interface with Simple Drag &
                                                 Drop Options
        correlation rules
       Create user-defined groups and
        variables for event correlation rules

CISCO MARS REPLACEMENT- SOLARWINDS LEM
                                            8
Power of Search

» Cisco MARS                                          » SolarWinds LEM
       The scope of search in MARS is                   LEM is equipped with a powerful
        basic and limited                                 and intuitive search option with
                                                          which you can explore search log
       The method of search is not                       data visually.
        very simple
                                                         It also allows you to use search
                                                          tools like Word Clouds, Tree-
                                                          maps, Bubble Charts and
                                                          Histograms.



                                   Notable here is the Word Clouds -
                       the first implementation ever in a log monitoring system.

CISCO MARS REPLACEMENT- SOLARWINDS LEM
                                                  9
Power of Search (Contd…)

»      Not just search, LEM allows you to
       store log data in a centralized
       repository.

»      Compares original log data and
       normalized event data side-by-side
       and     easily found with LEM’s
       various search options.

»      Eliminates the need for additional
       hardware with a high compression
       data model that stores data at up
       to a 60:1 compression ratio.               LEM’s Advanced & Intuitive IT Search Options




    CISCO MARS REPLACEMENT- SOLARWINDS LEM
                                             10
Compliance Reporting

»     LEM comes with 300+ "audit-
      proven" compliance reports to
      comply with so many federal
      policies like PCI DSS, GLBA, SOX,
      NERC CIP, HIPAA and even more.

»     You can run these policies
      through LEM to get graphical
      report summaries from the
      extensive resource of log data
      that were captured in real-time.

»     Cisco MARS is not equipped with
                                             Select Your Choice of Regulatory Compliance Policies and Run Reports Using LEM
      such a store of compliance
      reports




    CISCO MARS REPLACEMENT- SOLARWINDS LEM
                                                       11
Incident Response

»     With a library of built-in Active Responses LEM
      executes the automated responses needed to
      mitigate threats and respond to operational
      issues, security breaches, malware and policy
      violations immediately.

»     LEM doesn’t need any integration with any
      Incident Response system.

»     Whereas Cisco MARS which requires
      integration with Cisco Intrusion Prevention
      System (IPS) to respond and take action on             LEM’s Active Response Technology in Action
      real-time security threats.



    Some of LEM’s Active Responses include quarantining infected machines, blocking IP
    addresses, disabling user accounts, killing unauthorized processes and restarting services.



    CISCO MARS REPLACEMENT- SOLARWINDS LEM
                                                        12
Device Support

»       MARS is focused on Cisco networking devices
»       SolarWinds LEM extends support to network devices from dozens of
        manufacturers, hundreds of products, and thousands of models and
        various operating systems and applications.




                                         Supports Multiple Devices
CISCO MARS REPLACEMENT- SOLARWINDS LEM
                                                           13
Test Drive an Alternative for MARS

»       SolarWinds’ best-in-class SIEM technology provides all-in-one affordable
        log and event analysis and management software that also performs
        active responses to react to real-time threats while complying with
        regulatory policies.




         Try out the fully-functional 30-day free trial to see LEM in action.

CISCO MARS REPLACEMENT- SOLARWINDS LEM
                                         14
Additional Security Recommendations

»      Some other key areas that you may need to equip yourself are:
           Firewall Security Management
           Network Change & Configuration Management
           Endpoint Vulnerability Management
           Endpoint Data Loss Preventions



»      You can read more from this whitepaper
       The Case for Security Information and
       Event Management (SIEM) in Proactive
       Network Defense




    CISCO MARS REPLACEMENT- SOLARWINDS LEM
                                             15
Thank You!




CISCO MARS REPLACEMENT- SOLARWINDS LEM
                                         16

Mais conteúdo relacionado

Semelhante a What is your alternative to Cisco MARS?

Overall Security Process Review CISC 6621Agend.docx
Overall Security Process Review CISC 6621Agend.docxOverall Security Process Review CISC 6621Agend.docx
Overall Security Process Review CISC 6621Agend.docx
karlhennesey
 
ManageEngine_SIEM_Log360_SOC.pptx
ManageEngine_SIEM_Log360_SOC.pptxManageEngine_SIEM_Log360_SOC.pptx
ManageEngine_SIEM_Log360_SOC.pptx
TriLe786508
 

Semelhante a What is your alternative to Cisco MARS? (20)

SolarWinds Log & Event Manager vs Splunk. What's the Difference?
SolarWinds Log & Event Manager vs Splunk. What's the Difference?SolarWinds Log & Event Manager vs Splunk. What's the Difference?
SolarWinds Log & Event Manager vs Splunk. What's the Difference?
 
CLOUD NATIVE SECURITY
CLOUD NATIVE SECURITYCLOUD NATIVE SECURITY
CLOUD NATIVE SECURITY
 
How-To: Linux Performance Monitoring & Management for your Multi-Vendor Network
How-To: Linux Performance Monitoring & Management for your Multi-Vendor Network How-To: Linux Performance Monitoring & Management for your Multi-Vendor Network
How-To: Linux Performance Monitoring & Management for your Multi-Vendor Network
 
Overall Security Process Review CISC 6621Agend.docx
Overall Security Process Review CISC 6621Agend.docxOverall Security Process Review CISC 6621Agend.docx
Overall Security Process Review CISC 6621Agend.docx
 
Setting up a secure development life cycle with OWASP - seba deleersnyder
Setting up a secure development life cycle with OWASP - seba deleersnyderSetting up a secure development life cycle with OWASP - seba deleersnyder
Setting up a secure development life cycle with OWASP - seba deleersnyder
 
Elastic SIEM (Endpoint Security)
Elastic SIEM (Endpoint Security)Elastic SIEM (Endpoint Security)
Elastic SIEM (Endpoint Security)
 
BMC - Response to the SolarWinds Breach/Malware
BMC - Response to the SolarWinds Breach/MalwareBMC - Response to the SolarWinds Breach/Malware
BMC - Response to the SolarWinds Breach/Malware
 
McAfee - Enterprise Security Manager (ESM) - SIEM
McAfee - Enterprise Security Manager (ESM) - SIEMMcAfee - Enterprise Security Manager (ESM) - SIEM
McAfee - Enterprise Security Manager (ESM) - SIEM
 
ClearArmor CSRP - 01.01 SOFTWARE BASED VULNERABILITIES
ClearArmor CSRP - 01.01 SOFTWARE BASED VULNERABILITIESClearArmor CSRP - 01.01 SOFTWARE BASED VULNERABILITIES
ClearArmor CSRP - 01.01 SOFTWARE BASED VULNERABILITIES
 
The Future of Embedded and IoT Security: Kaspersky Operating System
The Future of Embedded and IoT Security: Kaspersky Operating SystemThe Future of Embedded and IoT Security: Kaspersky Operating System
The Future of Embedded and IoT Security: Kaspersky Operating System
 
Cloud Security - Made simple
Cloud Security - Made simpleCloud Security - Made simple
Cloud Security - Made simple
 
ManageEngine_SIEM_Log360_SOC.pptx
ManageEngine_SIEM_Log360_SOC.pptxManageEngine_SIEM_Log360_SOC.pptx
ManageEngine_SIEM_Log360_SOC.pptx
 
Security Information Event Management - nullhyd
Security Information Event Management - nullhydSecurity Information Event Management - nullhyd
Security Information Event Management - nullhyd
 
Reactive Architecture
Reactive ArchitectureReactive Architecture
Reactive Architecture
 
Glenn Lazarus- Why Your Observability Strategy Needs Security Observability
Glenn Lazarus- Why Your Observability Strategy Needs Security ObservabilityGlenn Lazarus- Why Your Observability Strategy Needs Security Observability
Glenn Lazarus- Why Your Observability Strategy Needs Security Observability
 
McAfee Skyhigh: Elevating Your AWS Security Posture (SEC307-S) - AWS re:Inven...
McAfee Skyhigh: Elevating Your AWS Security Posture (SEC307-S) - AWS re:Inven...McAfee Skyhigh: Elevating Your AWS Security Posture (SEC307-S) - AWS re:Inven...
McAfee Skyhigh: Elevating Your AWS Security Posture (SEC307-S) - AWS re:Inven...
 
the_role_of_resilience_data_in_ensuring_cloud_security.pptx
the_role_of_resilience_data_in_ensuring_cloud_security.pptxthe_role_of_resilience_data_in_ensuring_cloud_security.pptx
the_role_of_resilience_data_in_ensuring_cloud_security.pptx
 
the_role_of_resilience_data_in_ensuring_cloud_security.pdf
the_role_of_resilience_data_in_ensuring_cloud_security.pdfthe_role_of_resilience_data_in_ensuring_cloud_security.pdf
the_role_of_resilience_data_in_ensuring_cloud_security.pdf
 
Tenable Solutions for Enterprise Cloud Security
Tenable Solutions for Enterprise Cloud SecurityTenable Solutions for Enterprise Cloud Security
Tenable Solutions for Enterprise Cloud Security
 
Symantec Best Practices for Cloud Security: Insights from the Front Lines
Symantec Best Practices for Cloud Security: Insights from the Front LinesSymantec Best Practices for Cloud Security: Insights from the Front Lines
Symantec Best Practices for Cloud Security: Insights from the Front Lines
 

Mais de SolarWinds

Mais de SolarWinds (20)

SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...
SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...
SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...
 
SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...
SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...
SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...
 
Government Webinar: Alerting and Reporting in the Age of Observability
Government Webinar: Alerting and Reporting in the Age of ObservabilityGovernment Webinar: Alerting and Reporting in the Age of Observability
Government Webinar: Alerting and Reporting in the Age of Observability
 
Government and Education Webinar: Full Stack Observability
Government and Education Webinar: Full Stack ObservabilityGovernment and Education Webinar: Full Stack Observability
Government and Education Webinar: Full Stack Observability
 
Government and Education Webinar: Public Sector Cybersecurity Survey - What I...
Government and Education Webinar: Public Sector Cybersecurity Survey - What I...Government and Education Webinar: Public Sector Cybersecurity Survey - What I...
Government and Education Webinar: Public Sector Cybersecurity Survey - What I...
 
Becoming Secure By Design: Questions You Should Ask Your Software Vendors
Becoming Secure By Design: Questions You Should Ask Your Software VendorsBecoming Secure By Design: Questions You Should Ask Your Software Vendors
Becoming Secure By Design: Questions You Should Ask Your Software Vendors
 
Government and Education Webinar: Real-Time Mission, CIO, and Command Dashboards
Government and Education Webinar: Real-Time Mission, CIO, and Command DashboardsGovernment and Education Webinar: Real-Time Mission, CIO, and Command Dashboards
Government and Education Webinar: Real-Time Mission, CIO, and Command Dashboards
 
Government and Education Webinar: Simplify Your Database Performance Manageme...
Government and Education Webinar: Simplify Your Database Performance Manageme...Government and Education Webinar: Simplify Your Database Performance Manageme...
Government and Education Webinar: Simplify Your Database Performance Manageme...
 
Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...
Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...
Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...
 
Government and Education Webinar: Leverage Automation to Improve IT Operations
Government and Education Webinar: Leverage Automation to Improve IT OperationsGovernment and Education Webinar: Leverage Automation to Improve IT Operations
Government and Education Webinar: Leverage Automation to Improve IT Operations
 
Government and Education Webinar: Improving Application Performance
Government and Education Webinar: Improving Application PerformanceGovernment and Education Webinar: Improving Application Performance
Government and Education Webinar: Improving Application Performance
 
Government and Education: IT Tools to Support Your Hybrid Workforce
Government and Education: IT Tools to Support Your Hybrid WorkforceGovernment and Education: IT Tools to Support Your Hybrid Workforce
Government and Education: IT Tools to Support Your Hybrid Workforce
 
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
 
SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...
SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...
SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...
 
Government and Education Webinar: Zero-Trust Panel Discussion
Government and Education Webinar: Zero-Trust Panel Discussion Government and Education Webinar: Zero-Trust Panel Discussion
Government and Education Webinar: Zero-Trust Panel Discussion
 
Government and Education: Leveraging The SolarWinds Orion Assistance Program ...
Government and Education: Leveraging The SolarWinds Orion Assistance Program ...Government and Education: Leveraging The SolarWinds Orion Assistance Program ...
Government and Education: Leveraging The SolarWinds Orion Assistance Program ...
 
Government and Education Webinar: SQL Server—Advanced Performance Tuning
Government and Education Webinar: SQL Server—Advanced Performance Tuning Government and Education Webinar: SQL Server—Advanced Performance Tuning
Government and Education Webinar: SQL Server—Advanced Performance Tuning
 
Government and Education Webinar: Recovering IP Addresses on Your Network
Government and Education Webinar: Recovering IP Addresses on Your NetworkGovernment and Education Webinar: Recovering IP Addresses on Your Network
Government and Education Webinar: Recovering IP Addresses on Your Network
 
Government and Education Webinar: Optimize Performance With Advanced Host Mon...
Government and Education Webinar: Optimize Performance With Advanced Host Mon...Government and Education Webinar: Optimize Performance With Advanced Host Mon...
Government and Education Webinar: Optimize Performance With Advanced Host Mon...
 
Government and Education Webinar: Conquering Remote Work IT Challenges
Government and Education Webinar: Conquering Remote Work IT Challenges Government and Education Webinar: Conquering Remote Work IT Challenges
Government and Education Webinar: Conquering Remote Work IT Challenges
 

Último

Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Victor Rentea
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
WSO2
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 

Último (20)

Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistan
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
Cyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdfCyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdf
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 

What is your alternative to Cisco MARS?

  • 1. Have you planned your replacement for Cisco MARS? © 2013, SolarWinds Worldwide, LLC. All rights reserved. 1
  • 2. Agenda 1. Why should you find a replacement now? 2. What to look for in a replacement tool? 3. Why SolarWinds could be the right alternative a. Deployment b. Event Correlation c. Power of Search d. Compliance Reporting e. Incident Response f. Device Support 4. Additional Security Recommendations CISCO MARS REPLACEMENT- SOLARWINDS LEM 2
  • 3. Why should find a replacement now? » What’s up with Cisco MARS?  Cisco has decided it is right time for the hardware to not be sold in the market and it has been scrapped for new purchases Do you have a plan B?  Cisco no longer sells Cisco Security We have one for you… Monitoring, Analysis and Response Check how SolarWinds Log and System (MARS) Event Manager (LEM) can help?  Read the End-of-Life Notice to learn more CISCO MARS REPLACEMENT- SOLARWINDS LEM 3
  • 4. What to look for in a replacement tool? » Best-in-class SIEM technology provides:  All-in-one affordable log and event analysis  Active responses to react to real-time threats while complying with regulatory policies » Also a SIEM tool that has in-memory analytics that can capture, correlate and respond to network attacks and insider abuse at network speed. CISCO MARS REPLACEMENT- SOLARWINDS LEM 4
  • 5. Why SolarWinds could be your alternative Let us consider the top 6 decisive factors: 1. Deployment 2. Event-Correlation functionality 3. Power of Search 4. Compliance Reporting 5. Incident Response 6. Device Support » See how SolarWinds Log and Event Manager (LEM) compares to Cisco MARS on all the above parameters. CISCO MARS REPLACEMENT- SOLARWINDS LEM 5
  • 6. Deployment » Cisco MARS » SolarWinds LEM  It is a hardware appliance which  Its a virtual appliance which requires physical setup and downloads and deploys in just network connections to become under an hour. fully operational.  It is not a standalone solution,  LEM is all equipped own its but part of Cisco Security own and needs no supporting Management Suite which needs and add-on devices or modules the support of Cisco Security to deliver its full service. Manager (CSM) to deliver the full extent of service. CISCO MARS REPLACEMENT- SOLARWINDS LEM 6
  • 7. Event Correlation » Cisco MARS » SolarWinds LEM  It comes with the complexity of  As a standalone product, uses defining and building its multi-dimensional correlation rules to handle correlation engine to detect multiple device and multiple behavioral anomalies in real- events time.  Relies on Cisco CSM to perform  It also employs a simple and event correlation easy-to-use rule builder with familiar drag and drop interface, icon-based tool panel and graphical object selection panel. LEM also comes with 700+ pre-built correlation rules that cover critical network infrastructure, change management and network security functions. CISCO MARS REPLACEMENT- SOLARWINDS LEM 7
  • 8. Event Correlation (Contd…) » SolarWinds LEM can:  Correlate time-based and transaction- based events  Send notifications and trigger actions based on event correlation that happens in-memory  Perform multiple event correlation  Ability to set independent thresholds for activity per event, or group of events  Leverage non-linear event correlation  Access to field-level data for event LEM’s Correlation Rule Builder Interface with Simple Drag & Drop Options correlation rules  Create user-defined groups and variables for event correlation rules CISCO MARS REPLACEMENT- SOLARWINDS LEM 8
  • 9. Power of Search » Cisco MARS » SolarWinds LEM  The scope of search in MARS is  LEM is equipped with a powerful basic and limited and intuitive search option with which you can explore search log  The method of search is not data visually. very simple  It also allows you to use search tools like Word Clouds, Tree- maps, Bubble Charts and Histograms. Notable here is the Word Clouds - the first implementation ever in a log monitoring system. CISCO MARS REPLACEMENT- SOLARWINDS LEM 9
  • 10. Power of Search (Contd…) » Not just search, LEM allows you to store log data in a centralized repository. » Compares original log data and normalized event data side-by-side and easily found with LEM’s various search options. » Eliminates the need for additional hardware with a high compression data model that stores data at up to a 60:1 compression ratio. LEM’s Advanced & Intuitive IT Search Options CISCO MARS REPLACEMENT- SOLARWINDS LEM 10
  • 11. Compliance Reporting » LEM comes with 300+ "audit- proven" compliance reports to comply with so many federal policies like PCI DSS, GLBA, SOX, NERC CIP, HIPAA and even more. » You can run these policies through LEM to get graphical report summaries from the extensive resource of log data that were captured in real-time. » Cisco MARS is not equipped with Select Your Choice of Regulatory Compliance Policies and Run Reports Using LEM such a store of compliance reports CISCO MARS REPLACEMENT- SOLARWINDS LEM 11
  • 12. Incident Response » With a library of built-in Active Responses LEM executes the automated responses needed to mitigate threats and respond to operational issues, security breaches, malware and policy violations immediately. » LEM doesn’t need any integration with any Incident Response system. » Whereas Cisco MARS which requires integration with Cisco Intrusion Prevention System (IPS) to respond and take action on LEM’s Active Response Technology in Action real-time security threats. Some of LEM’s Active Responses include quarantining infected machines, blocking IP addresses, disabling user accounts, killing unauthorized processes and restarting services. CISCO MARS REPLACEMENT- SOLARWINDS LEM 12
  • 13. Device Support » MARS is focused on Cisco networking devices » SolarWinds LEM extends support to network devices from dozens of manufacturers, hundreds of products, and thousands of models and various operating systems and applications. Supports Multiple Devices CISCO MARS REPLACEMENT- SOLARWINDS LEM 13
  • 14. Test Drive an Alternative for MARS » SolarWinds’ best-in-class SIEM technology provides all-in-one affordable log and event analysis and management software that also performs active responses to react to real-time threats while complying with regulatory policies. Try out the fully-functional 30-day free trial to see LEM in action. CISCO MARS REPLACEMENT- SOLARWINDS LEM 14
  • 15. Additional Security Recommendations » Some other key areas that you may need to equip yourself are:  Firewall Security Management  Network Change & Configuration Management  Endpoint Vulnerability Management  Endpoint Data Loss Preventions » You can read more from this whitepaper The Case for Security Information and Event Management (SIEM) in Proactive Network Defense CISCO MARS REPLACEMENT- SOLARWINDS LEM 15
  • 16. Thank You! CISCO MARS REPLACEMENT- SOLARWINDS LEM 16