ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    GDPR galore

    IT Discussion
    privacy regulatory logging
    5
    7
    1.6k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • matteo nunziatiM
      matteo nunziati
      last edited by matteo nunziati

      OK,

      here in Europe they are starting spread FUD about GDPR and consequences if you are not aligned. One of the things which seems useful to pass the inspection (don't really mind about what can be useful to be compliant de facto) is a log monitoring system like ELSA.

      Now I'm new to this kind of stuff and I know about ELSA as a name just because of a post on linked in.

      Basic question is: what would you use for centralized logging and inspection in a mixed env (linux + windows)? Any hint is welcome as I'm just aware of syslog for centralized logging in linux envs, but I'm quite new to windows, to not say about any tool for analysis and reporting (and I also hate it already!).

      1 Reply Last reply Reply Quote 0
      • coliverC
        coliver
        last edited by

        Check out the ELK or Graylog stack. They seem to be standard centralized logging systems.

        scottalanmillerS stacksofplatesS 2 Replies Last reply Reply Quote 3
        • scottalanmillerS
          scottalanmiller @coliver
          last edited by

          @coliver said in GDPR galore:

          Check out the ELK or Graylog stack. They seem to be standard centralized logging systems.

          Those are by far the two big ones. Also Splunk if you have really deep pockets.

          1 Reply Last reply Reply Quote 2
          • hobbit666H
            hobbit666
            last edited by

            Yeah I've been hearing a lot on this GDPR stuff luckily I'm not involved and others in the dept are lol.

            But what logs would they need you to collect and store? We don't do this at the moment but if required would like to start looking at solutions. So I'm prepared for the "can you do this and get it installed" lol

            matteo nunziatiM 1 Reply Last reply Reply Quote 0
            • stacksofplatesS
              stacksofplates @coliver
              last edited by stacksofplates

              @coliver said in GDPR galore:

              Check out the ELK or Graylog stack. They seem to be standard centralized logging systems.

              I would go with Graylog unless you want to build some type of authentication mechanism for ELK (now Elastic Stack). Graylog has RBA built in along with alerting and other nice tools. We got a quote from Elastic for a 6 node cluster with their auth front end stuff and it was going to be $55,000 a year.

              scottalanmillerS 1 Reply Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller @stacksofplates
                last edited by

                @stacksofplates said in GDPR galore:

                @coliver said in GDPR galore:

                Check out the ELK or Graylog stack. They seem to be standard centralized logging systems.

                I would go with Graylog unless you want to build some type of authentication mechanism for ELK (now Elastic Stack). Graylog has RBA built in along with alerting and other nice tools. We got a quote from Elastic for a 6 node cluster with their auth front end stuff and it was going to be $55,000 a year.

                That's why we use GL instead of ELK.

                1 Reply Last reply Reply Quote 0
                • matteo nunziatiM
                  matteo nunziati @hobbit666
                  last edited by

                  @hobbit666 said in GDPR galore:

                  Yeah I've been hearing a lot on this GDPR stuff luckily I'm not involved and others in the dept are lol.

                  But what logs would they need you to collect and store? We don't do this at the moment but if required would like to start looking at solutions. So I'm prepared for the "can you do this and get it installed" lol

                  Bah. Here in italy they are stressing a lot the access control. And they want centralized lig inspection to check for logins (not necessarily a valid point from a tech perspective but they ask for)

                  1 Reply Last reply Reply Quote 1
                  • 1 / 1
                  • First post
                    Last post