View Cart  

EventLog Analyzer

ManageEngine EventLog analyzer is licensed based on the number of log sources (devices, applications, Windows servers, and workstations) added for monitoring.

Note: If you monitor an application and also the server in which the application is installed, then you will be licensed for 1 log source.
Enter value for atleast one primary component. +
ico-get-quo-ban

Thank you for your interest in EventLog Analyzer.

Please fill-up the form to get a personalized quote, that best suits your requirements. Our sales representative will get back to you shortly.

   
 
Number of Log Sources
( Windows Servers, Linux/Unix , Firewalls, Routers, Switches, IDS/IPS, AS400, Microsoft SQL Server, IIS Sites and Other applications)
Number of Endpoints
(Windows Workstation)
Number of Cloud Accounts
(AWS Accounts, Microsoft 365 Tenants)
 
   
 
Onboarding and Implementation (optional)
By signing up, I agree to the terms of service and Privacy Policy.
 
Compare Editions EventLog Analyzer is available in two editions viz., Premium and Distributed Edition.
×
Features Free Edition * Premium Distributed
Multiple OS Support Available Available Available
Monitored Device Support
(Windows, Linux, Unix, AIX, Routers, Switches, VMWare,
Any Syslog device)
Available Available Available
Customizable dashboard widgets Available Available Available
Log search using boolean operator, phrase, value ranges, wildcards & grouped search Available Available Available
FTP Active Mode support for log file import Available Available Available
Import and Analyze Event files Available Available Available
Auto Discovery of Hosts Available Available Available
Filter Events before Storing in Database Available Available Available
Compressed Archives Available Available Available
Archive log files encryption Available Available Available
Hashing and Time stamping of Archive log files Available Available Available
Real-time Display of Events Available Available Available
Automated Alerts Available Available Available
Authorized Access Available Available Available
Host Grouping for Policy Implementation Available Available Available
Schedule Data Collection Available Available Available
Custom Reports Available Available Available
Scheduling Reports Available Available Available
PUMA Reports Available Available Available
Multiple Report Formats Available Available Available
Multi-level Drilldown Available Available Available
Trend Analysis Available Available Available
Security Analysis Available Available Available
Compliance Reports (EventLog & Syslog) (Predefined and Customization) Available Available Available
Command Execution on Alerts Available Available Available
SMS and SNMP Trap Notification for Alerts Available Available Available
Internationalization Support to handle Native Logs Available Available Available
Export/Import of Alert, Report, and Filter Profiles Available Available Available
Advanced Search in Raw Logs, Save Result as Report Profile Available Available Available
Scheduled import from local and remote (FTP/SFTP) machines Available Available Available
Log collection during log collector down time Available Available Available
Monitoring Users Accessing EventLog Analyzer Application Available Available Available
File Integrity Monitoring   Available Available
Server specific reports     Available
Multi-geographical location monitoring     Available
Scalable architecture     Available
Log field extraction using an interactive regular expression (regex) syntax builder   Available Available
Universal log parsing and indexing (ULPI) to support any log format (Human Readable & non-encrypted log formats)   Available Available
Import users from Active Directory groups   Available Available
Agent for log collection across WAN/Firewalls   Available Available
Import of saved Syslog Files   Available Available
Re-branding Web Client   Available Available
Instant Reports   Available Available

Analyze Application specific Logs

  • MS IIS Web server
  • MS IIS FTP servers
  • DHCP Windows server
  • DHCP Linux server
  • MS SQL database
  • Oracle database
  • Apache Web server
  • Print server
  Available Available
Support for MS SQL Server and MS SQL Cluster as Backend Database   Available Available
Custom View & User based Views   Available Available
Active Directory & RADIUS Server based Third Party User Authentication   Available Available
IBM AS/400 Logs Analysis (V5R series) Filter, Report, Alert, Archive & Import   Available Available
Real-Time Event Correlation   Available Available
Windows Terminal Server Log Monitoring   Available Available
User Session Monitoring   Available Available

Cloud Source Auditing

  • AWS Cloud Logs
  Available Available
Compare Models Here's a more detailed breakdown of all the services included in both plans to help you decide:
×
Event Log Analyzer Service Offering Standard Onboarding Advanced Onboarding
Installation Tick Tick
Device management Windows Server - 10, WKS - 50, Supported Syslog Devices -10 Tick
Application management - IIS, MSSQL, Other Applications Up to 1 each Up to 3 each
Technician management (role configuration) Tick Tick
Log collection filter configuration Tick Tick
Log retention policy settings Tick Tick
Configuring Windows/Linux-based file monitoring basic configuration Tick Up to 10
Tuning product administrative settings
1. Email and SMS server configuration
2. Configuring log collection failure alerts
3. Log forwarding
Tick Tick
Historic EVT/EVTX file import Cross Tick
Custom reports and alerts configuration (provided logs are available) Up to 1 each Up to 10 in total
Reports, alerts, and compliance schedule creation Up to 1 each Up to 10
Rule-based correlation setup (based on the feasibility/available logs) Up to 1 Up to 5
Configuring managed servers* Cross Tick
Compliance-specific reports configuration Cross Up to 1
Dashboard customization Cross Up to 5
Log import scheduling Cross Up to 5
Custom log parser rule (creating additional fields) (subject to feasibility) Cross Tick
Advanced Threat Analytics configuration** Cross Tick
Incident management configuration Cross Tick
SOAR workflow configuration Cross Tick
External threat feed configuration Cross Tick
Setting up Windows logging Cross Tick
Security hardening & privacy
1. SSL configuration
2. Configuring TFA
3. GDPR privacy configuration
4. CAPTCHA
Cross Tick
Database migration (PGSQL to MSSQL) Cross Tick
High availability configuration Cross Tick
Restoration of an available backup Cross Tick
Data migration (ES/archive) Cross Tick
Agent deployment (agent-level registry changes will be performed) Cross Tick
NAT configuration Cross Tick
Expert consultation Cross Tick
Comprehensive documentation Cross Tick
User acceptance testing Cross Tick
Integrated walkthrough Cross Tick
Signing Cross Tick
Post-implementation health check Cross Tick
Supporting new log formats (subject to feasibility) Cross Tick
Additional custom correlation rules configuration (based on the feasibility/available logs) Cross Tick
Training (up to 4 participants) Available as an add-on Tick

* - only for distributed editions and MSSPs
** - if license is purchased

Note: The implementation of the above services are subject to fulfilment of client deliverables outlined in the scope of work (SOW).