System and Method to Customize a Security Log Analyzer
Systems and methods adapted to customize a security log analyzer to recognize a security log, the system including at least one network security device for processing data traffic on a data network, the network security device associated with at least one computing device, and adapted to generate a security log, the system further including rule builder software adapted to generate a rule for recognizing at least one item in a security log and a log analyzer adapted to apply the rule in analyzing a security log.
1 . A system adapted to customize a security log analyzer to recognize a security log, the system comprising at least one network security device adapted to process data traffic on a data network, the network security device associated with at least one computing device and adapted to generate a security log, the system further including a means for generating at least one rule for recognizing at least one log item in a security log and a log analyzer adapted to apply the at least one rule in analyzing a security log.
2 . The system in accordance with claim 1 , the means for generating at least one rule comprising rule builder software.
3 . The system in accordance with claim 1 , the rule comprising a rule type and rule item name.
4 . The system in accordance with claim 3 wherein the rule type indicates the type of security element selected from at least one of a source IP address or a timestamp.
5 . The system in accordance with claim 3 wherein the rule item name comprises information for the recognition of a security element.
6 . The system in accordance with claim 2 wherein the rule builder software is associated with the computing device, the computing device further comprising an input module and an output module.
7 . The system in accordance with claim 6 , the rule builder software adapted to display information to an operator via the output module and receive information from the operator via the input module to generate the rule comprising a rule type and a rule item name.
8 . The system in accordance with claim 7 wherein the rule builder software is adapted to display a plurality of security element type choices at the output module.
9 . The system in accordance with claim 8 wherein the rule builder is adapted to set the rule type to the security element type choice based on operator input.
10 . The system in accordance with claim 1 , the log analyzer comprising software running on the computing device, the software adapted to process at least one log item in a security log to recognize a security element based on the rule.
11 . The system in accordance with claim 1 wherein the log analyzer comprises at least one rule.
12 . A method of customizing a security log analyzer to recognize a security log, comprising generating at least one rule for recognizing at least one item in the security log and associating the rule with the log analyzer.
13 . The method in accordance with claim 12 wherein the security log analyzer is associated with a system comprising at least one network security device adapted to process data traffic on a data network, the network security device associated with at least one computing device and adapted to generate a security log, the system further including a means for generating at least one rule for recognizing at least one item in a security log, and the security log analyzer is adapted to apply the at least one rule in analyzing a security log.
14 . The method in accordance with claim 12 , the method comprising providing, in a computing device associated with a network security device, rule builder software adapted to create the rule comprising at least a rule type and rule item name.
15 . The system in accordance with claim 14 wherein the rule type indicates the type of security element selected from at least one of a source IP address or a timestamp.
16 . The system in accordance with claim 14 wherein the rule item name comprises information for the recognition of a security element.
17 . A method for recognizing at least one log item in a security log comprising generating a rule for recognizing at least one log item in a security log and processing the log item in a security log analyzer to recognize a security element based on the rule.
18 . The method in accordance with claim 17 wherein the security log analyzer is associated with a system comprising at least one network security device adapted to process data traffic on a data network, the network security device associated with at least one computing device and adapted to generate a security log, the system further including a means for generating at least one rule for recognizing at least one log item in a security log.
19 . The method in accordance with claim 17 , the method comprising providing, in a computing device associated with a network security device, rule builder software adapted to create a rule comprising at least a rule type and a rule item name.
20 . The system in accordance with claim 19 wherein the rule type indicates the type of security element selected from at least one of a source IP address or a timestamp.
21 . The system in accordance with claim 19 wherein the rule item name comprises information for the recognition of a security element.