"The marriage of [these] technologies creates a better way for the enterprise to safeguard itself from threats that could compromise the network"
— Mike Montecillo, analyst, Enterprise Management Associates
 

    Quick Contact

    First Name:

    Last Name:

    Company:

    Email:

    Phone:

    State:

    What can we do for you?

      


    Click here for more contact options.

  •  

 
 

NitroView - Application Monitor

Application Data Monitor



Application Data Monitor

NitroView Data base Monitor
How to Buy
Contact Us to request a demo, or
call us at 888-LOG-SIEM

Features at a Glance
Full compliance audit & reporting of application contents

Monitor and enforce corporate and industry usage policies

Discover sensitive data in emails, IM, web apps, file shares and more

Detect threat and/or fraud activity

Supports hundreds of applications and protocols

Full session awareness from login to logoff

Policy-based and anomaly-based detection

Fully integrated with NitroView ESM to support advanced security and compliance use cases

Easy to deploy, easy to use

More Information
NitroView Application Data Monitor (ADM) Datasheet
NitroSecurity Solution Brochure
Awards
Testimonials
ADM Product Specs

NitroView ADM is an Application Data Monitoring appliance that is fully integrated into the NitroView enterprise security management solution. NitroView ADM provides deep packet inspection of application traffic, providing full decode of application data- and meta-data, for maximum visibility into how applications are being used in your network.

NitroView ADM provides:

  • Inspection of all application traffic
  • Full content inspection of over 500 applications and documents, including email attachments & compressed documents
  • Monitoring of protocols for misuse or anomalies

When NitroView ADM detects a policy violation or protocol anomaly, an alert is generated with full details of the event. This allows NitroView ESM to correlate application events directly to other security events, including intrusion attempts, traffic anomalies, IPS or firewall alerts, authentication failures, and more. The ability to correlate across all systems provides superior threat detection capability for better overall security.

In addition, NitroView ADM allows for full application session analysis—ideal for compliance reporting and audit purposes. Now, if a user is involved in an application policy violation, the entire session can be analyzed for evidence of fraud or data theft, with a clear audit trail already in place. The result is exceptional compliance management, which can be performed operationally, or used to feed hundreds of pre-defined compliance reports for GLBA, HIPAA, FISMA, NERC, PCI, SOX, and other regulatory requirements.

SIEM & ADM — Together

Like all NitroSecurity products, NitroView ADM is fully integrated with NitroView ESM. That means unparalleled correlation of highly detailed log, event, and network flow information. It also means lower operational costs, because NitroView provides a single user interface for all information management, and also for all device- and policy- configuration. That means true "single pane of glass" management for intrusion prevention, threat detection, incident response, fraud detection, data loss protection, and compliance. For CISO's, that means efficient, powerful security operations. For CFO's, that means lower costs, both for initial capital expenses, and also for ongoing operational costs.

Already have a SIEM? Use NitroView ADM as standalone application monitoring tool. NitroView ADM can forward events to other SIEM or Log Management devices, or be used on its own to improve security and compliance.

An Easy Alternative to DLP

For enterprises looking to protect against data loss with a more efficient and cost-effective solution, content-aware SIEM is the perfect solution. CA-SIEM can track and analyze how protected information is accessed and used on the network, to detect unintentional data loss, deliberate theft of data, and violations of business policies that could put sensitive information at risk.

Because NitroView is built for the analysis of database activity and application data contents in addition to logs and events, it's able to provide many DLP functions in addition to its many security operations, forensics, and compliance capabilities. The result is a single platform that solves multiple business needs through a common system, using a single interface — further reducing costs through a reduction in operational costs. These capabilities go far beyond what is offered by other SIEMs — rather than relying on database and application logs to detect threats against your data, we're able to provide active monitoring: providing full database session visibility to know exactly what data is being accessed, when, and by who; and going beyond surface visibility of application logs to detect sensitive data within the applications themselves.

More than just logs

Many SIEM products claim fraud detection and "application support." However, these systems rely on application logs, which provide varying degrees of application event detail depending upon the application. Some systems go even further to provide analysis of packet header information, to tie specific events to a given application. Both solutions lack the full depth of application monitoring that can be provided using a dedicate ADM. Unlike logs and packet headers, full ADM provides visibility into the application's content—including:

  • Text within an email
  • The contents of an email attachment
  • Instant message conversations
  • The contents of files transfered over IM
  • The presence of sensitive or protected information
  • The absence of corporate privacy statement in outbound emails
  • Virtually any policy violation based on how applications and documents are used

Specifications

NitroView Application Data Monitor Specifications

Select a Model for Specifications

Model                        Description      Throughput      Interfaces     
NS-ADM-2230-R NitroView ADM 2000, Application Data Monitor, (1) 1U Appliance 1Gbps 4 copper 10/100/1000
NS-ADM-1225-R NitroView ADM 1000, Application Data Monitor, (1) 1U Appliance 500Mbps 4 copper 10/100/1000

Click to see a current list of supported applications


Click to see a current list of supported protocols


Related Products

NitroView Database Monitor Specifications

Select a Model for Specifications

Model                  Description      Appliance      Supported DBs      Events/Sec     
NS-DBM-4245-R NitroView DBM 4000, Database Monitor Pack. 1U Appliance good DB2, Oracle, MS SQL, MySQL, SyBase 15,000
NS-DBM-2250-R NitroView DBM 2000, Database Monitor Pack. 1U Appliance goodDB2, Oracle, MS SQL, MySQL, SyBase 10,000
NS-DBM-2230-R NitroView DBM 2000, Database Monitor Pack. 1U Appliance goodDB2, Oracle, MS SQL, MySQL, SyBase 5,000

NitroView Enterprise Security Manager Specifications

Select a Model for Specifications [Note: for US Army APL approved models, please visit our government site]

Model           Description                         Events/sec     Report   
speed*    
HDD**    
NS-ELM-XXXX NitroView Enterprise Log Manager (ELM) Integrated Log Management for NitroView ESM & NitroView Receiver
 NS-ESM-X5 NitroView ESM X5 "High Speed" Enterprise Security Manager provides Log Analysis, SIEM, and Network Analysis functions for large enterprise networks. 7TB local storage plus 500GB of in-memory storage for etremely high performance. One 3U appliance, plus one 2U Appliance. 40 Million 1 Billion events/sec 7TB +
500GB RAM
 NS-ESM-5750-R NitroView ESM 5000 Enterprise Security Manager provides Log Analysis, SIEM, and Network Analysis functions for medium to large enterprise networks. 7TB local storage. 3U Appliance. 4 Million 100 Million events/sec 7 TB
 NS-ESM-5510-R NitroView ESM 5000 Enterprise Security Manager provides Log Analysis, SIEM, and Network Analysis functions. 3.75TB local storage, 3U appliance 3 Million 50 Million events/sec 3.75 TB
 NS-ESM-5205-R NitroView ESM 5000 Enterprise Security Manager provides Log Analysis, SIEM and Network Analysis functions. 2.5TB local storage. 3U appliance. 2 Million 25 Million events/sec 2.5 TB
 NS-ESMRCV-5205-R NitroView ESM 5000 Enterprise Security Manager provides Log Analysis, SIEM and Network Analysis functions. Includes integrated NitroView Receiver for collection of third party feeds. 2.5 TB local storage. 3U appliance. Rated for 5,000 events per second and manages up to (5) NitroSecurity devices (IPS, DAM, or APM). 5,000 25 Million events/sec 2.5 TB
 NS-ESMRCV-4245-R NitroView ESM 4000 Enterprise Security Manager provides Log Analysis, SIEM and Network Analysis functions. Includes integrated NitroView Receiver for collection of third party feeds. 1.5 TB local storage. 1U appliance. Rated for 1,000 events per second and manages up to (3) NitroSecurity devices (IPS, DAM, or APM). 1,000 25 Million events/sec 1.5 TB
 NS-NRC-4245 NitroView Receiver, collects 3rd party logs, events and flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 18,000 events per second. 18,000 - 1 TB
 NS-NRC-2250 NitroView Receiver, collects 3rd party logs, events and flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 15,000 events per second. 15,000 - 1 TB
 NS-NRC-2230 NitroView Receiver, collects 3rd party logs, events and flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 10,000 events per second. 10,000 - 1 TB
 NS-NRC-1225 NitroView Receiver, collects 3rd party logs, events and flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 5,000 events per second. 5,000 - 500GB
 NS-ESS-5205 NitroView ESM 5000 Enterprise Security Server provides management for up to 10 NitroSecurity devices (IPS, DAM, or APM). Does not support 3rd party feeds. Redundant power, 2.5TB local storage. 3U appliance. 150,000 (NitroSecurity devices only) 25 Million events/sec 2.5 TB
 NS-ESS-2230-R NitroView ESM 2000 Enterprise Security Server provides management for up to 10 NitroSecurity devices (IPS, DAM, or APM). Does not support 3rd party feeds. 500GB local storage. 1U appliance. 150,000 (NitroSecurity devices only) 15 Million 500GB

* Typical SIEM reports (queries) will complete in a few seconds, even on very large event stores.

** NitroView ESM 5000 models utilize a raid 10 drive configuration, as well as redundant, dedicated drives for OS storage. The number listed above represents the usable capacity for event, log and flow storage.

*** The maximum number of supported devices per ESM is determined by the receiver model(s) used for collection.

Click to see a current list of supported data sources


NitroView Enterprise Log Manager Specifications

Select a Model for Specifications

model              Description      Logs / Sec     
NS-ESMLM-4245-R NitroView ESM / ELM 4000 Enterprise Security Manager provides SIEM , Compliant Enterprise Log Management, and Network Analysis functions. Includes integrated NitroView Receiver for collection of third party feeds. 1 TB local storage. 1U appliance. 1,000
NS-ESMLM-5205-R NitroView ESM / ELM 5000 Enterprise Security Manager provides SIEM , Compliant Enterprise Log Management, and Network Analysis functions. Includes integrated NitroView Receiver for collection of third party feeds. 2.5 TB local storage. 3U appliance. 2,500
NS-ESMLM-5510-R NitroView ESM / ELM 5000 Enterprise Security Manager provides SIEM , Compliant Enterprise Log Management, and Network Analysis functions. Includes integrated NitroView Receiver for collection of third party feeds. 3.75 TB local storage. 3U appliance. 5,000
NS-ELM-5510-R NitroView ELM 5000 Enterprise Log Manager provides Compliant Log Management functions. 3.75 TB local storage. 3U appliance. 35,000
NS-ELM-5205-R NitroView ELM 5000 Enterprise Log Manager provides Compliant Log Management functions. 2.5 TB local storage. 3U appliance. 20,000
NS-ELM-4245-R NitroView ELM 4000 Enterprise Log Manager provides Compliant Log Management functions. Supports network / SAN storage options. No local storage. 1U appliance. 40,000
NS-ELM-5750-R NitroView ELM 5000 Enterprise Log Manager provides Compliant Log Management functions. 7 TB local storage. 3U appliance. 50,000
NS-NRCLM-4245-R NitroView ELM Receiver provides compliant Log Management and collects flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 10,000 events per second. 10,000
NS-NRCLM-2250-R NitroView ELM Receiver provides compliant Log Management and collects flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 8,000 events per second. 8,000
NS-NRCLM-2230-R NitroView ELM Receiver provides compliant Log Management and collects flow data for correlation and analysis by NitroView ESM. 1U Appliance. Rated for 5,000 events per second. 5,000
NS-LC-2250-R NitroView LogCaster 2000, 1U appliance. Includes (500) LogCaster Agent Licenses. Rated for 10,000 events per second. 10,000
NS-LC-2230-R NitroView LogCaster 2000, 1U appliance. Includes (250) LogCaster Agent Licenses. Rated for 5,000 events per second. 5,000
NS-LC-AGT-200 NitroView LogCaster Large Syslog Device Agent License for quantity 200 devices. Includes console software; supports *NIX Server, Firewall, IPS, etc... -
NS-LC-AGT-100 NitroView LogCaster Large Syslog Device Agent License for quantity 100 devices. Includes console software; supports *NIX Server, Firewall, IPS, etc... -
NS-LC-AGT-50 NitroView LogCaster Large Syslog Device Agent License for quantity 50 devices. Includes console software; supports *NIX Server, Firewall, IPS, etc... -
NS-LC-AGT-25 NitroView LogCaster Large Syslog Device Agent License for quantity 25 devices. Includes console software; supports *NIX Server, Firewall, IPS, etc... -

NitroGuard IPS Specifications

Select a Model for Specifications [Note: for US Army APL approved models, please visit our government site]

Model                     Description      Throughput      Copper
Ports     
Fiber
Ports     
NS-IPS-5450-R NitroGuard IPS 5000, 3U IPS appliance supporting approximately 4 to 5Gbps & 1.2m connections. Includes redundant power and a bypass NIC. 4-6 Gbps 12x1Gbps 4x10Gbps
NS-IPS-4245-R NitroGuard IPS4000, 1U IPS appliance supporting approximately 2Gbps & 1.5m connections. Includes redundant power and a bypass NIC. 2 Gbps 2, 4, 8 2, 4
NS-IPS-2250-R NitroGuard IPS 2000, 1U IPS appliance supporting approximately 750Mbps & 1.2m connections. Includes redundant power and a bypass NIC. 750 Mbps 2, 4, 8 2, 4
NS-IPS-2230-R NitroGuard IPS 2000, 1U IPS appliance supporting approximately 500Mbps & 1.2m connections. Includes redundant power and a bypass NIC. 500 Mbps 2, 4, 8 2, 4
NS-IPS-1225 NitroGuard IPS 1000, 1U IPS appliance supporting approximately 250Mbps & 1.2m connections. Includes single power and a bypass NIC. 250 Mbps 2, 4 2, 4
NS-IPS-1160 NitroGuard IPS 1000, 1U IPS appliance supporting approximately 150Mbps & 1.2m connections. Includes single power and bypass NIC. 150 Mbps 2 N/A
NS-IPS-110 NitroGuard IPS 100, Set-Top IPS appliance supporting approximately 50Mbps & 1.2m connections. Includes single power and a 2 port 10/100/1000 Base-TX copper NIC (no bypass). 50 Mbps 2 N/A





These icons link to social bookmarking sites to help share this content.
  • bodytext
  • del.icio.us
  • Reddit
  • Slashdot
  • Technorati
  • Propeller
  • TwitThis
              
 

Search NitroSecurity.com