EventLog Analyzer

Centralises log data for event investigation, auditing, correlation and reporting.

Built for estates where logs from infrastructure and applications need central analysis.

Centralise log data for search, analysis and reporting

Logs are often distributed across network devices, servers and applications, with different formats and retention needs. Finding related events or reviewing a change can require teams to search several separate sources.

EventLog Analyzer collects and parses this data into a central, searchable log record. It supports event correlation, file activity monitoring, reporting and log archiving, helping teams investigate activity and retain records for audit and review.

Where EventLog Analyzer is used

EventLog Analyzer is suited to investigating events across infrastructure and application logs, including syslogs from network devices. Teams can search raw data, correlate events from different sources and use predefined or custom reports for review.

It also records file and folder access, permission changes and data value changes on Windows and Linux servers. Predefined rules can create tickets in integrated ITSM tools or start automated workflows.

Fits within these solutions

Security Information & Event Management
File Activity Monitoring
Log Management & Analysis
Compliance Reporting
Security Orchestration, Automation & Response
Extended Detection & Response

Delivery & deployment

On-Premises Software
SaaS / Cloud

Suitable environments

EventLog Analyzer fits environments with log-producing network devices, servers, databases, web servers and applications. Its file activity monitoring applies to Windows and Linux servers, while its built-in syslog server collects and analyses syslogs from network devices.

Benefits

Central Event Record

Brings log data into a central record for investigation, audit activity and reporting.

Faster Event Investigation

Search and correlation help teams examine related activity across different log sources.

File Change Evidence

Records file access and changes for later investigation and review.

Retained Log Records

Log archiving retains data for selected periods alongside predefined or custom reports.

Capabilities

Log Collection

Collects logs from more than 750 sources through agents, agentless collection and log importing.

Custom Log Parsing

Parses human-readable log formats and extracts fields through a custom log parser.

Event Correlation

Correlates events from different log sources using predefined or custom rules.

Raw Log Search

Searches raw log data with basic, grouped, range and query-builder searches.

File Activity Monitoring

Monitors file access, permission changes and data value changes on Windows and Linux servers.

Reporting and Archiving

Generates predefined or custom reports and archives log data for selected periods.

Common Use Cases

Network Syslog Analysis

Collect and analyse syslogs from network devices using the built-in syslog server.

Security Event Review

Correlate events from multiple log sources when reviewing security-related activity.

File Change Review

Review file and folder access, permission changes and data value changes on supported servers.

ITSM Ticket Creation

Create tickets in integrated ITSM tools from predefined rules.

Part of (depending on licence)

Resources

Screenshots

How would you like to proceed?