I use NeuSecure, which has been bought up about 3 times in the last six months. Currently, IBM owns the product.
I LOVE this console (SIM solution). I feed events from all core assets and have now got a handle on what's going on out there. The downside to any of these beasts is cost and the effort needed to tune them properly. Another nasty is bug discovery which seems to happen more so with products with "bigger than life" feature sets.
I looked at NetForensics product which was absolute crap and also at CAs offering which was less than user friendly.
ArcSite was another one I looked at but the pricing, $150 grand, left it way out of reach.
Anyway, another 2 cents.
--TH13




Reply With Quote