Risk-based Prioritization
LogRhythm automatically prioritizes each event based on its impact to your business' operations.
LogRhythm's risk-based prioritization calculates a 100 point priority based on the:
- Type of event
- Likelihood event is a false alarm
- The threat rating of the host causing the event (e.g., remote attacker), and
- The risk rating of the server on which the event occurred
LogRhythm's risk-based priority helps ensure the most important events are identified and acted upon.
The impact of an event varies by business and within a business, by system. For instance, a router link failure might not be immediately critical for an ISP with redundant routers. However, for a branch office with a single router, business is impacted until fixed. A server reboot is uninteresting if seen on a user workstation but when seen from an ERP server that has 99.999% uptime requirements, is extremely interesting.
Event Forwarding
Identified log entries having the most immediate operational relevance are forwarded to the Event Manager. This typically includes security events, audit failures, warnings and errors. Event forwarding rules work “out of the box.” You also have the ability to tailor those rules to your liking and create your own rules. The function of intelligently forwarding a subset of logs provides the first layer of data reduction.
Log activity for specific filename patterns, IP addresses, hosts or users can also be monitored easily. When security policies are violated, LogRhythm can automatically alert designated individuals via e-mail, pager, existing management applications and the LogRhythm console.
Because only the most important log entries are forwarded as events, users are extremely efficient with time they spend using the LogRhythm solution. Instead of having to weed through numerous irrelevant log entries, the most important logs are automatically identified for them.
LogRhythm features contextual event forwarding, which enables real-time identification and alerting of anomalies within application, database and network activity. For example, LogRhythm can be used to pinpoint specific exceptions such as transactions greater than a specified dollar amount in a financial application, including when it occurred, who was responsible, and which account was modified.
User-Driven Log Analysis
Once logs are collected, classified, normalized, prioritized, stored and correlated, some rise to the level of an “event”. The LogRhythm Event Management function applies the real-time monitoring, alerting, incident management and response appropriate for specific events. Some events warrant a deeper investigation beyond the events themselves to include other related log data. For these situations LogRhythm offers a comprehensive set of investigative capabilities ranging from high-level trending and visualization to monitoring in real time the activities associated with a specific user, system, device or information asset.
LogMart
The LogRhythm LogMart tool incorporates a powerful set of visualization, data trending and search capabilities. LogMart aggregates millions of logs in a single graphical view, which can expose exceptions in security, compliance and operations over short or long periods of time. The powerful user-configurable charting and filtering capabilities enable users to quickly switch from viewing months or even years worth of log trend data to drilling down to individual logs exposing the root cause of a security breach or operational problem.

Click Image To View Entire LogRhythm Screen