1. Catalogs
  2. Extreme Networks
  3. Security Information & Event Manager (SIEM)
video corpo

Security Information & Event Manager (SIEM)

Security Information & Event Manager (SIEM)

Security Information & Event Manager (SIEM)

Product catalog summary
Benefits
  • Streamlines NOC and SOC operations by focusing on actionable data, reducing the need to interpret numerous daily events.
  • Employs advanced surveillance and forensic analysis for threat awareness, including inappropriate content and data theft.
  • Enhances existing network and security infrastructure with rapid deployment and efficiency improvements.
  • Integrates with Extreme Networks and third-party security products for comprehensive threat detection and remediation.
  • Virtual Flow Collector enables network behavior analysis and Layer 7 visibility in virtual infrastructures.
  • Supports large enterprises with modular components and high availability functionality.
Product Overview

The Extreme Networks Security Information and Event Manager (SIEM) combines detection methodologies with behavioral analysis and third-party vulnerability assessments for intelligent security management. It prioritizes vulnerabilities for immediate response, enhancing IT staff effectiveness.

  • Provides threat management, log management, compliance reporting, and operational efficiency.
  • Correlates and prioritizes network activity data, security events, and external threat data for improved remediation.
  • Baselines normal network behavior to identify and report anomalies for potential attacks or vulnerabilities.
Compliance and High Availability

Offers extensive logging, trend information, and reports for compliance with standards like COBIT, GLB, HIPAA, PCI, and Sarbanes Oxley. High Availability (HA) functionality ensures data availability during failures, with automatic failover and data replication.

Features
  • SIEM All-In-One and Base Appliances offer security intelligence with flexible deployment, event collection, and traffic analysis.
  • SIEM Flow Anomaly Processor enhances flow data processing and interfaces with Behavioral Flow Sensors.
  • SIEM Event Processor supports up to 10,000 events per second for enhanced event data processing.
  • SIEM Network Behavioral Flow Sensors enable application-layer flow analysis and anomaly detection.
  • SIEM Virtual Flow Collectors provide visibility and functionality for virtual network infrastructures.
  • SIEM Console Manager distributes flow and log processing while maintaining a global network view.
Specifications

All SIEM appliances support RAID 10 for high availability and redundancy. They offer various models with different processing capacities and upgrade options for flow and event processing.

Specifications:
Key specifications for SIEM appliances include:
  • Processor: Quad-Core Intel Xeon Processor at 2.4 GHz.
  • Memory: 6 GB to 48 GB depending on the model.
  • Storage: 160 GB SATA drives and 9 x 1TB 7200 SATA 3.5'' drives.
  • Network Interfaces: 4x10/100/1000 Base-T and 4X1000 Base-SX.
  • Power Supply: 502 W to 675W, with redundant options available.
Environmental Specifications:
Operating conditions for the appliances include:
  • Operating Temperature: 10º C to 35º C.
  • Storage Temperature: -40º C to 65º C.
  • Operating Humidity: 20% to 80% non-condensing.
  • Storage Humidity: 5% to 95% non-condensing.
  • Operating Altitude: -16 m to 3,048 m.
System Requirements:
For the SIEM Virtual Flow Collector System:
  • VMware ESXi 4.0.
  • VMware Infrastructure Client.
  • 512 MB of free memory and 36 GB of free disk space on the VMware host.
Regulatory Standards:
Compliance with safety and EMC standards includes:
  • Safety: UL 60950-1, EN 60950-1, IEC 60950-1, etc.
  • EMC: FCC 47 CFR Part 15 (Class A), EN 55022 (Class A), etc.
  • Environmental: RoHS Directive, WEEE Directive, etc.
Product Models and Upgrades:
Details on SIEM models and capabilities include:
  • DSIMBA7-SE and DSIMBA7-LX for all-in-one management.
  • Various upgrade options for flow and event processing capacities.
  • Virtual appliances like DVSIEM for scalable management solutions.
Ordering Information:
Information on ordering SIEM appliances and components includes:
  • External flow and event processors.
  • Additional log sources and flow sensors.
  • Power cords must be ordered separately.
Warranty and Support:
Extreme Networks offers a one-year warranty against manufacturing defects and provides comprehensive service and support options tailored to customer needs.
See more

Catalog excerpts

Security Information & Event Manager (SIEM)-1

DATA SHEET Security Information & Event Manager (SIEM) Compliance through Security Information and Event Management, Log Management, and Network Behavioral Analysis Delivers fast, accurate data about security threats: • Enables NOC and SOC staff to focus on actionable information rather than struggle to interpret millions of daily events generated by network security appliances, switches, routers, servers, and applications • Uses advanced surveillance and forensics analysis to deliver situational awareness of both external and internal threats including inappropriate content, IM, file transfers, traffic from undesirable geographies, data theft, and malicious worm infections • Leverages existing investments in network and security infrastructure while accelerating time to value through out-of-box functionality, rapid deployment, and staff efficiency gains • Integrates with Extreme Networks Intrusion Prevention System (IPS), Network Access Control (NAC), and NMS Automated Security Manager solutions to provide a unified, realtime view of the threat landscape and effectively detect, isolate, and automatically remediate threats • Integrates with a broad array of third party security and network products, including firewalls and routers, for the highest level of visibility and protection • Virtual Flow Collector allows the analysis of network behavior and enables Layer 7 visibility within virtual infrastructures • Meets the deployment requirements of the largest enterprises with modular component options and easily deployed high availability functionality - Severity of an attack - Importance of the affected asset - Identity of the attacker - Credibility of data sources - Identification of abnormal behavior Product Overview The Extreme Networks Security Information and Event Manager (SIEM) product combines best-in-class detection methodologies with behavioral analysis and information from third party vulnerability assessment tools to provide the industry’s most intelligent security management solution. Extreme Networks SIEM delivers actionable information to effectively manage the security posture for organizations of all sizes. The challenge created by most threat detection systems is the volume of information they generate — making it difficult to determine which vulnerabilities require an immediate, high priority response. The Extreme Networks SIEM solution addresses this challenge and provides powerful tools that enable the security operations team to proactively manage complex IT security infrastructures. Extreme Networks Security Information and Event Manager: • Goes beyond traditional security information and event managers and network behavioral analysis products to deliver threat management, log management, compliance reporting, and increased operational efficiency • Collects and combines network activity data, security events, logs, vulnerability data, and external threat data into a powerful management dashboard that intelligently correlates, normalizes, and prioritizes — greatly improving remediation and response times, and greatly enhancing the effectiveness of IT staff • Baselines normal network behavior by collecting, analyzing, and aggregating network flows from a broad range of networking and security appliances including JFlow, NetFlow, and SFlow records. It then discerns network traffic patterns that deviate from this norm, flagging potential attacks or vulnerabilities — anomalous behavior is captured and reported for correlation and remediation Security Information & Event Manager – Data Sheet

 Open the catalog to page 1
Security Information & Event Manager (SIEM)-2

• Tracks extensive logging and trend information, and generates a broad range of reports for network security, small central site or enterprise department may have higher event and flow collection rate requirements. The SIEM Appliance for network optimization, and regulatory compliance purposes; Small Enterprises (model DSIMBA7-SE) provides an ideal all-in-one report templates are provided for COBIT, GLB, HIPAA, PCI, option for these environments. The SIEM Enterprise Base Appliance models (DSIMBA7-LX All SIEM appliances offer High Availability (HA) functionality and DSIMBA7-LU) provide a range...

 Open the catalog to page 2
Security Information & Event Manager (SIEM)-3

source/destination TCP port, and IP protocol used. SIEM Network the virtual network infrastructure. A SIEM Virtual Flow Collector is a Behavioral Flow Sensors are deployed at strategic points in the virtual appliance that enables the analysis of network behavior and network to collect IP traffic flow information from a broad range Layer 7 visibility within the enterprise’s virtual infrastructure. SIEM of networked devices — including switches, routers, security Virtual Flow Collectors support up to 10,000 flows per minute and appliances, servers, and applications. SIEM Network Behavioral monitoring...

 Open the catalog to page 3
Security Information & Event Manager (SIEM)-4

Hard Disk Network Interfaces Power Supply * Note: Higher Scalability beyond the upgrade options can be achieved using External Flow Anomaly Processors & Event Processors SIEM CONSOLE MANAGER MODEL SIEM Virtual Console Manager SIEM Console Manager Appliance N/A (External Virtual Flow Anamoly Processor Required) N/A (External Flow Anamoly Processor Appliance Required) N/A (External Virtual Event Processor Required) N/A (External Event Processor Applaince Required) Appliance Form Factor 2 x Quad-Core Intel Xeon Processor; Frequency: 2.4 GHz; L3 Cache: 12 MB Hard Disk Network Interfaces Power Supply...

 Open the catalog to page 4
Security Information & Event Manager (SIEM)-5

SIEM EVENT PROCESSOR MODEL SIEM Virtual Event Processor SIEM Event Processor Appliance Upgrade Options Appliance Form Factor Software License Upgrades Additional Event processing: DVEVP-200E-UP, DVEVP-500EUP, DVEVP-1KE-UP Software License Upgrades Additional Event processing: DSEVPS7-UP 2 x Quad-Core Intel Xeon Processor; Frequency: 2.4 GHz; L3 Cache: 12 MB Hard Disk Network Interfaces Power Supply ** The maximum event processing may require an optional license upgrade. SIEM FLOW PROCESSOR MODEL SIEM Virtual Flow Processor SIEM Flow Processor Appliance Base: 15,000 Flows Maximum: 50,000 Flows...

 Open the catalog to page 5

All Extreme Networks catalogs and technical brochures

  1. SLX 9640

    6  Pages

  2. WiNG AP 8432

    4  Pages

  3. WiNG AP 7532

    7  Pages

  4. A-Series A4

    7  Pages

  5. X670-G2-DS

    11  Pages

  6. A-Series

    7  Pages

  7. 800-Series

    8  Pages

  8. 7100G-Series

    7  Pages

  9. Altitude 4600

    7  Pages

  10. AP3825

    12  Pages

  11. Summit X430

    6  Pages

  12. Summit X460-G2

    15  Pages

  13. OneController

    4  Pages

  14. Summit X670-G2

    11  Pages

  15. K-Series

    13  Pages

  16. Mobile IAM

    3  Pages

  17. Ridgeline

    11  Pages

  18. I-Series

    4  Pages

  19. G-Series

    7  Pages

  20. 7100-Series

    5  Pages

  21. DSSumX670_1777

    10  Pages

  22. PAG_1002.

    9  Pages

  23. DSSummitX460

    12  Pages

  24. Summit 48si

    4  Pages

  25. Summit WM3411

    7  Pages

  26. XENPAK

    3  Pages

  27. ExtremeWare

    5  Pages

  28. EAS Series

    6  Pages

  29. Altitude 4511

    3  Pages

  30. Alpine

    5  Pages

*Prices are pre-tax. They exclude delivery charges and customs duties and do not include additional charges for installation or activation options. Prices are indicative only and may vary by country, with changes to the cost of raw materials and exchange rates.