Network World
Thursday, January 8, 2009
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Clear Choice Test

Security Information and Event Management

Introduction|Are SIEM and log management the same thing?|How we did it|Slideshow|Test archive

NetResults
Product QRadar TriGeo SIM Cinxi
Vendor Q1 Labs TriGeo Network Security High Tower Software
Price $19,000 $19,000 $18,000
Pros Well-rounded product; mature correlation engine; includes geographical lookups. Easy to use; has such additional functions as built-in intrusion detection; good for small businesses. Very easy to use; has built-in ticketing system; good user interface.
Cons User interface and feature organization still a bit rough. Expensive once you start adding extra features. Reporting and ad hoc querying remain quite weak.

Product Security Manager Eventia SecureVue
Vendor NetIQ Check Point Software eIQ Networks
Price* $850 per device monitored* $16,000 $50,000
Pros Useful data-manipulation tools; integrates with performance-and availability-monitoring tools. Natural addition for existing Check Point customers; provides essential features. Capable of importing performance and change-control information; unique visualization tool; excellent parser toolkit.
Cons Complex; installation is taxing; immature syslog listener, poor ad-hoc-query functions. DoesnÕt support as many devices as others do; no grouping mechanisms. User interface is painful; limited access to correlation logic.
Scorecard
Category Weight Q1 Labs
QRadar
HighTower
Cinxi
TriGeo
TriGeo SIM
NetIQ Security
Manager
Check Point
Eventia
eIQ
SecureVue
Event reduction 20% 4.0 3.0 2.0 3.0 2.0 2.0
Ad hoc querying 20% 3.0 2.0 4.0 2.0 2.0 2.0
Reporting 20% 3.0 2.0 3.0 3.0 2.0 2.0
User interface 20% 3.0 4.0 2.5 3.0 3.0 2.0
Installation 10% 3.0 3.0 3.0 3.0 3.0 3.0
Device support 10% 4.0 4.0 3.0 2.0 4.0 4.0
Scoring key: 5: Exceptional; 4: Very good; 3: Average; 2: Below average; 1: Subpar or not available.