<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Application Security Log Output Standards &#8211; Gartner&#8217;s View</title>
	<atom:link href="http://raffy.ch/blog/2007/09/04/application-security-log-output-standards-gartners-view/feed/" rel="self" type="application/rss+xml" />
	<link>http://raffy.ch/blog/2007/09/04/application-security-log-output-standards-gartners-view/</link>
	<description>Log visualization and log management as seen by Raffael Marty</description>
	<lastBuildDate>Thu, 26 Jan 2012 07:17:42 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Amrit</title>
		<link>http://raffy.ch/blog/2007/09/04/application-security-log-output-standards-gartners-view/comment-page-1/#comment-8455</link>
		<dc:creator>Amrit</dc:creator>
		<pubDate>Fri, 28 Sep 2007 05:16:47 +0000</pubDate>
		<guid isPermaLink="false">http://raffy.ch/blog/2007/09/04/application-security-log-output-standards-gartners-view/#comment-8455</guid>
		<description>Raffy,

Thanks for taking the time to review the document. Originally I wrote this to address a large series of calls from clients that were dealing with in many cases hundreds, yes hundreds, of internal applications. 99.99% of the time the log output for these internal applications was limited to debug information for the developers, if anything all. The majority of these customers were also undertaking a SIEM or log management initiative and struggling to configure the SIEMs/log managers to collect data from these customer defined data sources. At the same time I was doing some research on  web services security and was running into a similar issue - hundreds of internally developd applications (primarily web-based in this area) with organizations looking to improve the security, most of which had a centralized method for log management. At the time there was nothing readily available that wasn&#039;t tainted by a vendor perspective that I could provide these folks as a foundation to implement a standard log output for internally developed applications. I wasn&#039;t looking to boil the ocean, just get an organization to implement a policy that all internally developed applications would generate security oriented log output that could be easily consumed by a internally developed, or commercial log management system or SIEM. I also worked closely with the IAM/user provisioning analysts who were taking similar calls from their constituents.

Anyway I think your feedback is valid, although perhaps a bit nitpicky ;-)</description>
		<content:encoded><![CDATA[<p>Raffy,</p>
<p>Thanks for taking the time to review the document. Originally I wrote this to address a large series of calls from clients that were dealing with in many cases hundreds, yes hundreds, of internal applications. 99.99% of the time the log output for these internal applications was limited to debug information for the developers, if anything all. The majority of these customers were also undertaking a SIEM or log management initiative and struggling to configure the SIEMs/log managers to collect data from these customer defined data sources. At the same time I was doing some research on  web services security and was running into a similar issue &#8211; hundreds of internally developd applications (primarily web-based in this area) with organizations looking to improve the security, most of which had a centralized method for log management. At the time there was nothing readily available that wasn&#8217;t tainted by a vendor perspective that I could provide these folks as a foundation to implement a standard log output for internally developed applications. I wasn&#8217;t looking to boil the ocean, just get an organization to implement a policy that all internally developed applications would generate security oriented log output that could be easily consumed by a internally developed, or commercial log management system or SIEM. I also worked closely with the IAM/user provisioning analysts who were taking similar calls from their constituents.</p>
<p>Anyway I think your feedback is valid, although perhaps a bit nitpicky <img src='http://raffy.ch/blog/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
</channel>
</rss>

