SIEM Integrated Security Analytics
What are the essential reasons for needing SIEM?
- It collects, normalizes, and correlates logs from dozens of security devices in one place to detect complex attacks.
This is a proven solution with the highest number of references in the country and a record of processing 38TB daily at the largest A institution in the country.
What is the minimum scale required for implementation?
- There are no scale limitations for implementation. Small-scale setups can be configured with a single server, while large-scale setups can be flexibly expanded into distributed clusters.
If you provide the daily log volume and the number of connected devices, we can suggest the optimal configuration.
What types of logs can be collected and how are they integrated?
- We collect all types of logs including firewalls, IPS, WAF, DDoS, servers, DB, and cloud.
- Collection methods: Supports both Agent and Agentless
- Protocols: DB, File, UDP, Syslog, HTTP, SFTP, etc.
- Over 5,000 validated parser libraries available
Is it possible to migrate from existing ESM/SIEM?
- Yes, it is possible. We support the transfer of device integration information, detection rule sets, and operational data, and we carry out the migration in stages to ensure there are no security gaps.
We have the most migration implementation experience in the country.
How long does the implementation period take?
Generally, it takes 1 to 3 months. Small-scale (single institution) projects take about 1 to 3 months, while large-scale (including multiple affiliated institutions) projects may take more than 6 months.
The exact schedule will be proposed after discussing the environment.
Is there any impact on existing operational equipment when installing the Agent?
- The Agent is designed to have minimal impact, reducing the load on existing operational equipment.
In line with recent technological trends, we either minimize the role of the Agent or primarily support Agentless (API) processing.
What OS and DBMS do you use?
- The operating system used is Oracle Linux. Data management operates under two structures.
① Log data storage — A proprietary file index-based search engine is used, and SecureLayer does not store logs in a separate commercial database.
Logs are stored and processed through a file indexing structure via a high-speed search engine based on Lucene, allowing for real-time, rapid search and analysis of large volumes of logs.
② Auxiliary data management — MariaDB is used for managing auxiliary operational data such as statistical data and configuration information.
💡 Since log data is stored in a proprietary engine based on file indexing rather than a typical RDB (relational database), it ensures high performance and fast search speeds even in large-scale environments.
Is it possible to use in a network-separated environment?
Yes, it is possible. It can be independently configured in both work and internet network-separated environments, and we have numerous references for implementations in public institution network separation environments.
eyeCloudAI Assistant also operates in a closed network (not connected to the internet) environment.