Leveraging NetFlow Data In LogRhythm
In addition to accepting data in traditional formats such as syslog and SNMP, LogRhythm also can collect from the Cisco-developed formats, SDEE and NetFlow. Network flow data can play a significant role in both detecting and corroborating intrusions and extrusions, particularly when combined with log and event data from other devices and application. By accepting, processing and normalizing NetFlow, LogRhythm allows former Cisco MARS users to correlate NetFlow data against a comprehensive set of relevant event data – from Cisco and non-Cisco devices.
Presented by Chris Petersen, LogRhythm CTO, VP Engineering, Founder.