<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: siem]]></title>
    <link>http://securityratty.com/tag/siem</link>
    <description></description>
    <pubDate>Mon, 10 Nov 2008 21:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Links for 2008-12-02 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/ced4c9798279af16f5e1c222d68826d6</link>
      <guid>http://securityratty.com/article/ced4c9798279af16f5e1c222d68826d6</guid>
      <description><![CDATA[Tim's take on Information Security and PCI DSS: Beware PCI DSS Compliant solution vendors
PCI Blog - Compliance Demystified
IBM to start-up: Industry vet responds to recession
SIEM Market Narrows with...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://securitim.blogspot.com/2008/12/beware-pci-dss-compliant-solution.html">Tim's take on Information Security and PCI DSS: Beware PCI DSS Compliant solution vendors</a></li>
<li><a href="http://pcianswers.com/">PCI Blog - Compliance Demystified</a></li>
<li><a href="http://news.cnet.com/8301-1001_3-10110633-92.html">IBM to start-up: Industry vet responds to recession</a></li>
<li><a href="http://brightfly.com/content/view/610/">SIEM Market Narrows with High Tower 's Flameout</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/473277633" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/industry vet responds">industry vet responds</category>
      <category domain="http://securityratty.com/tag/siem market narrows">siem market narrows</category>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/pci blog">pci blog</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/compliance">compliance</category>
      <category domain="http://securityratty.com/tag/tim">tim</category>
      <category domain="http://securityratty.com/tag/tower">tower</category>
      <category domain="http://securityratty.com/tag/ibm">ibm</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/473277633/anton18">Links for 2008-12-02 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Monthly Blog Round-Up November 2008]]></title>
      <link>http://securityratty.com/article/1bdd878eaa6b7f3beec3fe92db4f4c7c</link>
      <guid>http://securityratty.com/article/1bdd878eaa6b7f3beec3fe92db4f4c7c</guid>
      <description><![CDATA[As we all know, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see today . These monthly round-ups is an attempt to remind...]]></description>
      <content:encoded><![CDATA[<p>As we all know, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see <em>today</em>. These <a href="http://chuvakin.blogspot.com/search/label/Monthly">monthly round-ups</a> is an attempt to remind people of useful content from the past month! If you are “too busy to read the blogs” (!), at least read <a href="http://chuvakin.blogspot.com/search/label/Monthly">these</a>.</p>  <p>So, here is my next <strong>monthly <a href="chuvakin.blogspot.com/">&quot;Security Warrior&quot; blog</a> </strong>round-up of top 5 popular posts/topics.</p>  <ol>   <li>Amazingly, this month by far the #1 post is my “'<a href="http://chuvakin.blogspot.com/2008/11/blogging-from-deepsec-2008-in-vienna.html">Blogging from DeepSec 2008 in Vienna</a>.” DeepSec was indeed an awesome conference.</li>    <li>Last month, I said that “SIEM bashing reached a new high.” OMFG. What should I say <a href="http://chuvakin.blogspot.com/2008/06/11-signs-that-your-siem-is-dog-or-you.html">now</a>? I dunno. In any case, “<a href="http://chuvakin.blogspot.com/2008/06/11-signs-that-your-siem-is-dog-or-you.html">11 Signs That Your SIEM Is A Dog or &quot;Raffy, You Killed SIM!&quot;</a> is on the top list. BTW, “<a href="http://www.matasano.com/log/661/pro-forma-06-punditry-results/">On Open Source in SIEM and Log Management</a>” is also again on the top list, to much of my amazement.</li>    <li>Again and again, <a href="http://chuvakin.blogspot.com/search/label/PCI">PCI compliance</a> is obviously still all the rage: <a href="http://chuvakin.blogspot.com/2008/02/must-do-logging-for-pci.html">MUST-DO Logging for PCI?</a> post was again propelled to a place in my monthly Top5 list. </li>    <li>Get a firewall AND a fire extinguisher, now, will ya? Is it too much to ask? :-) The post “<a href="http://pcianswers.com/2008/11/03/e-commerce-startups-deal-with-pci-compliance/">On Small Companies and PCI Compliance</a>” is on the Top list.</li>    <li>Shockingly, <a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html">AGAINx2</a> :-) this month, the &quot;<a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">Top 11 Reasons to Secure and Protect Your Logs</a>&quot; came up as on the Top list.&#160; BTW, see <a href="http://chuvakin.blogspot.com/search/label/poll">my other logging polls</a> and my other “top 11” lists. </li> </ol>  <p><a href="http://chuvakin.blogspot.com/search/label/Monthly">See you</a> in December. Also see my annual “Top Posts” (<a href="http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html">2007</a>)</p>  <p><strong>Possibly related posts / past monthly popular blog round-ups:</strong></p>  <ul>   <li><a href="http://chuvakin.blogspot.com/2008/11/monthly-blog-round-up-october-2008.html">Monthly Blog Round-Up - October 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html">Monthly Blog Round-Up - September 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html">Monthly Blog Round-Up - August 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/08/monthly-blog-round-up-july-2008.html">Monthly Blog Round-Up - July 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/07/monthly-blog-round-up-june-2008.html">Monthly Blog Round-Up - June 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/06/monthly-blog-round-up-may-2008.html">Monthly Blog Round-Up - May 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/05/monthly-blog-round-up-april-2008.html">Monthly Blog Round-Up - April 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/04/monthly-blog-round-up-march-2008.html">Monthly Blog Round-Up - March 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/03/monthly-blog-round-up-february-2008.html">Monthly Blog Round-Up - February 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/02/monthly-blog-round-up-january-2008.html">Monthly Blog Round-Up - January 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/01/monthly-blog-round-up-december-2007.html">Monthly Blog Round-Up - December 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-november-2007.html">Monthly Blog Round-Up - November 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-october-2007.html">Monthly Blog Round-Up - October 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/10/monthly-blog-round-up-september-2007.html">Monthly Blog Round-Up - September 2007</a> </li>    <li><a href="http://chuvakin.blogspot.com/2007/08/monthly-blog-round-up-august-2007.html">Monthly Blog Round-Up - August 2007</a> </li> </ul>  <p>&#160; </p>  <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:7192e29b-e335-4630-8b0b-dc37806d54ee" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati Tags: <a href="http://technorati.com/tags/blog" rel="tag">blog</a>,<a href="http://technorati.com/tags/security" rel="tag">security</a>,<a href="http://technorati.com/tags/loggings" rel="tag">loggings</a>,<a href="http://technorati.com/tags/monthly" rel="tag">monthly</a></div>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=CToyO"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=CToyO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=q2gTO"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=q2gTO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=uBDPO"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=uBDPO" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/473057574" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 13:24:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/monthly blog round-up">monthly blog round-up</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/blog round-up">blog round-up</category>
      <category domain="http://securityratty.com/tag/monthly">monthly</category>
      <category domain="http://securityratty.com/tag/top">top</category>
      <category domain="http://securityratty.com/tag/top list">top list</category>
      <category domain="http://securityratty.com/tag/annual top posts">annual top posts</category>
      <category domain="http://securityratty.com/tag/monthly round-ups">monthly round-ups</category>
      <category domain="http://securityratty.com/tag/pci">pci</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/473057574/monthly-blog-round-up-november-2008.html">Monthly Blog Round-Up November 2008</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-11-26 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/f0356a02e90f2b20cfc323d05698aafb</link>
      <guid>http://securityratty.com/article/f0356a02e90f2b20cfc323d05698aafb</guid>
      <description><![CDATA[Decurity Blog SIEM is NOT dead, but if High-Towers recent announcement is any indication it certainly will become a thinner herd in the very near...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://blog.decurity.com/index.php/dec_template/more/siem_the_quickening_begins/">Decurity Blog</a><br/>
SIEM is NOT dead, but if High-Tower’s recent announcement is any indication it certainly will become a thinner herd in the very near future.</li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/466989080" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 26 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/decurity blog siem">decurity blog siem</category>
      <category domain="http://securityratty.com/tag/high-towers recent announcement">high-towers recent announcement</category>
      <category domain="http://securityratty.com/tag/thinner herd">thinner herd</category>
      <category domain="http://securityratty.com/tag/dead">dead</category>
      <category domain="http://securityratty.com/tag/future">future</category>
      <category domain="http://securityratty.com/tag/indication">indication</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/466989080/anton18">Links for 2008-11-26 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[SIEM Is Not What Is SIEMs Nowadays...]]></title>
      <link>http://securityratty.com/article/b779ea5efa744a1cf0338332b0a8720f</link>
      <guid>http://securityratty.com/article/b779ea5efa744a1cf0338332b0a8720f</guid>
      <description><![CDATA[Aliso Viejo-based High Tower Software, a venture-backed developer of security, compliance, and log management software, has shut down

Wonna go into SIEM market, anybody

About me:...]]></description>
      <content:encoded><![CDATA["<span style="font-family:Arial, Helvetica;">Aliso Viejo-based High Tower Software, a venture-backed developer of security, compliance, and log management software, has shut down."<br /><br />Wonna go into SIEM market, anybody?<br /></span><div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=32OrN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=32OrN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=IK9BN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=IK9BN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=ArMaN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=ArMaN" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/465577883" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 25 Nov 2008 12:40:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/log management software">log management software</category>
      <category domain="http://securityratty.com/tag/tower software">tower software</category>
      <category domain="http://securityratty.com/tag/siem market">siem market</category>
      <category domain="http://securityratty.com/tag/compliance">compliance</category>
      <category domain="http://securityratty.com/tag/org">org</category>
      <category domain="http://securityratty.com/tag/wonna">wonna</category>
      <category domain="http://securityratty.com/tag/developer">developer</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/chuvakin">chuvakin</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/465577883/siem-is-not-what-is-siems-nowadays.html">SIEM Is Not What Is SIEMs Nowadays...</source>
    </item>
    <item>
      <title><![CDATA[CSI SIEM Summit Slides and Notes]]></title>
      <link>http://securityratty.com/article/2b72dfad65c1f793fb21be157bd6733d</link>
      <guid>http://securityratty.com/article/2b72dfad65c1f793fb21be157bd6733d</guid>
      <description><![CDATA[As I mentioned, I did this fun &quot;SIEM Summit&quot; at CSI 35th in DC . Here are my slides from the event; feel free to pick on them



SIEM: Is It What Is SIEMs? Security Information and Event Management...]]></description>
      <content:encoded><![CDATA[As I mentioned, I did this fun <a href="http://chuvakin.blogspot.com/2008/11/come-meet-at-csi-in-dc.html">"SIEM Summit" at CSI 35th in DC</a>. <a href="http://www.slideshare.net/anton_chuvakin/siem-is-it-what-is-siems-security-information-and-event-management-summit-at-csi-35th-conference-presentation">Here </a>are my slides from the event; feel free to pick on them :-)<br /><br /><br /><div style="width:425px;text-align:left" id="__ss_783449"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" href="http://www.slideshare.net/anton_chuvakin/siem-is-it-what-is-siems-security-information-and-event-management-summit-at-csi-35th-conference-presentation?type=powerpoint" title="SIEM: Is It What Is SIEMs? Security Information and Event Management Summit at CSI 35th Conference">SIEM: Is It What Is SIEMs? Security Information and Event Management Summit at CSI 35th Conference</a><object style="margin:0px" width="425" height="355"><param name="movie" value="http://static.slideshare.net/swf/ssplayer2.swf?doc=csisiemsummitrel-1227540196195652-9&stripped_title=siem-is-it-what-is-siems-security-information-and-event-management-summit-at-csi-35th-conference-presentation" /><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slideshare.net/swf/ssplayer2.swf?doc=csisiemsummitrel-1227540196195652-9&stripped_title=siem-is-it-what-is-siems-security-information-and-event-management-summit-at-csi-35th-conference-presentation" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"></embed></object><div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;">View SlideShare <a style="text-decoration:underline;" href="http://www.slideshare.net/anton_chuvakin/siem-is-it-what-is-siems-security-information-and-event-management-summit-at-csi-35th-conference-presentation?type=powerpoint" title="View SIEM: Is It What Is SIEMs? Security Information and Event Management Summit at CSI 35th Conference on SlideShare">presentation</a> or <a style="text-decoration:underline;" href="http://www.slideshare.net/upload?type=powerpoint">Upload</a> your own. (tags: <a style="text-decoration:underline;" href="http://slideshare.net/tag/security">security</a> <a style="text-decoration:underline;" href="http://slideshare.net/tag/siem">siem</a>)</div></div><div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=9pNqN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=9pNqN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=wKUsN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=wKUsN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=tPt8N"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=tPt8N" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/464406206" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 24 Nov 2008 11:45:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/siem">siem</category>
      <category domain="http://securityratty.com/tag/siem summit">siem summit</category>
      <category domain="http://securityratty.com/tag/csi 35th">csi 35th</category>
      <category domain="http://securityratty.com/tag/csi 35th conference">csi 35th conference</category>
      <category domain="http://securityratty.com/tag/event management summit">event management summit</category>
      <category domain="http://securityratty.com/tag/event">event</category>
      <category domain="http://securityratty.com/tag/security siem">security siem</category>
      <category domain="http://securityratty.com/tag/view slideshare presentation">view slideshare presentation</category>
      <category domain="http://securityratty.com/tag/security information">security information</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/464406206/csi-siem-summit-slides-and-notes.html">CSI SIEM Summit Slides and Notes</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-11-20 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/f0421d3d712a177576a6940fd9181128</link>
      <guid>http://securityratty.com/article/f0421d3d712a177576a6940fd9181128</guid>
      <description><![CDATA[Got SIEM? - Part IV eIQviews Customers tend to use SIEM technologies for more reactive efforts, such as post-event forensics, rather than as a true correlation solution to determine unusual behavior...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://blog.eiqnetworks.com/2008/11/20/got-siem-part-iv/">Got SIEM? - Part IV &laquo; eIQviews</a><br/>
Customers tend to use SIEM technologies for more reactive efforts, such as post-event forensics, rather than as a true correlation solution to determine unusual behavior or policy violations before they have a chance to affect systems and data.</li>
<li><a href="http://siemblog.com/?p=13">SIEM Blog &raquo; Unrestricted Data Collection for Maximum Compliance and Forensic Visibility</a></li>
<li><a href="http://beastorbuddha.com/2008/11/19/so-we-own-your-client-database-and-everything-important-to-you/">Beast Or Buddha &raquo; Blog Archive &raquo; So we own your client database and everything important to you&hellip;</a><br/>
Web Developer: “Just because you can do that doesn’t mean we have a major problem like you say it is. It’s just you that did it!”
SG dude: “Well more than likely, others have….we didn’t do anything fancy…”.
Web Developer: “Well nothing has ever happened so it’s just you guys!”
SG dude: “You have no logging”.
Web Developer: “We’ve never been hacked!”</li>
<li><a href="http://ondlp.com/2008/10/13/my-wife-finally-knows-what-i-do/">On Data Loss Prevention (DLP) &raquo; My Wife Finally Knows What I Do</a></li>
<li><a href="http://securosis.com/2008/11/10/the-two-kinds-of-security-threats-and-how-they-affect-your-life/">The Two Kinds Of Security Threats, And How They Affect Your Life | securosis.com</a><br/>
We get money for noisy threats, and get called paranoid freaks for trying to prevent quiet threats (which can still lose our organizations a boatload of money, but don’t interfere with the married CEO’s ability to flirt with the new girl in marketing over email).</li>
<li><a href="http://www.csoonline.com/article/461422/Marcus_Ranum_on_Network_Security">Marcus Ranum on Network Security - CSO Online - Security and Risk</a><br/>
The real best practices have been the same since the 1970s: know where your data is, who has access to what, read your logs, guard your perimeter, minimize complexity, reduce access to &quot;need only&quot; and segment your networks.</li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/460414088" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 20 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/data collection">data collection</category>
      <category domain="http://securityratty.com/tag/web developer">web developer</category>
      <category domain="http://securityratty.com/tag/siem">siem</category>
      <category domain="http://securityratty.com/tag/data loss prevention">data loss prevention</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/siem blog">siem blog</category>
      <category domain="http://securityratty.com/tag/security threats">security threats</category>
      <category domain="http://securityratty.com/tag/network security">network security</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/460414088/anton18">Links for 2008-11-20 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-11-19 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/359d830ca1e8df85568ee491fac7b4b0</link>
      <guid>http://securityratty.com/article/359d830ca1e8df85568ee491fac7b4b0</guid>
      <description><![CDATA[QualysGuard PCI Pass/Fail Status Criteria - Qualys
Press Releases - November 11, 2008 - Q1 Labs free, downloadable, log management and compliance product that provides organizations with visibility...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://www.qualys.com/products/pci/qgpci/pass_fail_criteria/">QualysGuard PCI Pass/Fail Status Criteria - Qualys</a></li>
<li><a href="http://www.q1labs.com/pr.php?id=711">Press Releases - November 11, 2008 - Q1 Labs</a><br/>
free, downloadable, log management and compliance product that provides organizations with visibility across their networks, data centers, and infrastructures</li>
<li><a href="http://www.cheapest-service.com/blog/2008/11/11/healthy-paranoia-top-50-internet-security-blogs/">&nbsp; Healthy Paranoia: Top 50 Internet Security Blogs&nbsp;by&nbsp;The Daily Netizen</a></li>
<li><a href="http://www.govcert.nl/symposium/audiovideo.html">GOVCERT.NL Symposium 2008</a></li>
<li><a href="http://sec.online.wsj.com/article/SB122461917614955373.html">Looking for Trouble - WSJ.com</a></li>
<li><a href="http://blog.clearnetsec.com/articles/2008/11/11/it%E2%80%99s-hard-to-build-a-smart-siem">ClearNet Security : It&rsquo;s hard to build a smart SIEM</a><br/>
If you find yourself evaluating SIEM products, dig in and investigate how each works - you don’t want yesterday’s product.</li>
<li><a href="http://www.thecomplianceauthority.rsvp1.com/articles/111908_taylor.shtm">PCI Perspectives by Dave Taylor</a></li>
<li><a href="http://physicsworld.com/blog/2008/09/killed_by_complexity_1.html">Lehman Bros 'killed by complexity' (physicsworld.com Blog) - physicsworld.com</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/459218630" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 19 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/internet security blogs">internet security blogs</category>
      <category domain="http://securityratty.com/tag/clearnet security">clearnet security</category>
      <category domain="http://securityratty.com/tag/dave taylor">dave taylor</category>
      <category domain="http://securityratty.com/tag/compliance product">compliance product</category>
      <category domain="http://securityratty.com/tag/healthy paranoia">healthy paranoia</category>
      <category domain="http://securityratty.com/tag/labs free">labs free</category>
      <category domain="http://securityratty.com/tag/press releases">press releases</category>
      <category domain="http://securityratty.com/tag/physicsworld">physicsworld</category>
      <category domain="http://securityratty.com/tag/siem products">siem products</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/459218630/anton18">Links for 2008-11-19 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Come Meet at CSI in DC]]></title>
      <link>http://securityratty.com/article/e6562d9c485cc52151697f063ce893ca</link>
      <guid>http://securityratty.com/article/e6562d9c485cc52151697f063ce893ca</guid>
      <description><![CDATA[If you are in DC, come meet me during/after SIEM Summit or catch me at the show floor (ask at Qualys booth
About me:...]]></description>
      <content:encoded><![CDATA[If you are in DC, come meet me during/after <a href="http://www.csiannual.com/conference/summit.php">SIEM Summit</a> or catch me at the show floor (ask at <a href="http://www.qualys.com/">Qualys </a>booth)<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=Pe95N"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=Pe95N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=aboGN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=aboGN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=2WaeN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=2WaeN" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/456058114" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 03:44:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/duringafter siem summit">duringafter siem summit</category>
      <category domain="http://securityratty.com/tag/qualys booth">qualys booth</category>
      <category domain="http://securityratty.com/tag/org">org</category>
      <category domain="http://securityratty.com/tag/floor">floor</category>
      <category domain="http://securityratty.com/tag/chuvakin">chuvakin</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/456058114/come-meet-at-csi-in-dc.html">Come Meet at CSI in DC</source>
    </item>
    <item>
      <title><![CDATA[Events per Second the difference between a target and an assurance]]></title>
      <link>http://securityratty.com/article/f9815504814bde06b74afe918ec8d827</link>
      <guid>http://securityratty.com/article/f9815504814bde06b74afe918ec8d827</guid>
      <description><![CDATA[Weve been getting a good few questions recently about how many Events Per Second a SIEM product support. Well, that depends on a few factors
The transport processing Syslog events takes up a heck of a...]]></description>
      <content:encoded><![CDATA[<p>We&rsquo;ve been getting a good few questions recently about how many Events
  Per Second a SIEM product support. Well, that depends on a few factors:</p>

<ul>
  <li><strong>The transport</strong> &ndash; processing Syslog events takes up
    a heck of a lot less processing power than collecting from a Windows box.
    Same with collecting data over an ODBC connection.</li>
</ul>]]></content:encoded>
      <pubDate>Sun, 16 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/events">events</category>
      <category domain="http://securityratty.com/tag/syslog events takes">syslog events takes</category>
      <category domain="http://securityratty.com/tag/siem product support">siem product support</category>
      <category domain="http://securityratty.com/tag/windows box">windows box</category>
      <category domain="http://securityratty.com/tag/questions recently">questions recently</category>
      <category domain="http://securityratty.com/tag/odbc connection">odbc connection</category>
      <category domain="http://securityratty.com/tag/lot">lot</category>
      <category domain="http://securityratty.com/tag/transport">transport</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1390">Events per Second the difference between a target and an assurance</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-11-10 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/e5dc439433ab04442decbc4c37c5a3a0</link>
      <guid>http://securityratty.com/article/e5dc439433ab04442decbc4c37c5a3a0</guid>
      <description><![CDATA[Got SIEM? - Part II eIQviews
SIEM ( Chapter Three SIEM) Im Namen Allahs, des Allerbarmers, des...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://blog.eiqnetworks.com/2008/11/09/got-siem-part-ii/">Got SIEM? - Part II &laquo; eIQviews</a></li>
<li><a href="http://kadalbuntunk.wordpress.com/2008/02/01/siem-chapter-three-%e2%80%93-siem/">SIEM ( Chapter Three &ndash; SIEM) &laquo; Im Namen Allahs, des Allerbarmers, des Barmherzigen</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/449199751" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 10 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/siem">siem</category>
      <category domain="http://securityratty.com/tag/des">des</category>
      <category domain="http://securityratty.com/tag/des allerbarmers">des allerbarmers</category>
      <category domain="http://securityratty.com/tag/allahs">allahs</category>
      <category domain="http://securityratty.com/tag/chapter">chapter</category>
      <category domain="http://securityratty.com/tag/eiqviews">eiqviews</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/449199751/anton18">Links for 2008-11-10 [del.icio.us]</source>
    </item>
  </channel>
</rss>
