About Members News Events Trainings Career Catalog Log In Join TR

Products

Features

Centralized Logging

  • The Centralized Log Management System collects and consolidates logs from multiple endpoint NGFW devices into a single platform. Users can click on any log-related chart to initiate a historical log search using the “Search Logs” option.

Statistical Capabilities

  • Antikor CLM generates visual statistics of logs received from endpoint NGFW devices, displaying graphs for session counts (allowed/dropped). It classifies and visualizes data by highest source IPs, destination IPs, services, and protocols.

Daily Session Statistics

  • Daily session statistics in Antikor CLM help assess network traffic load, user behavior, and system health. These metrics provide both quantitative and temporal insights into daily network activity.

Hourly Session Statistics

  • Hourly session statistics offer critical visibility into fluctuations in network traffic throughout the day. This is particularly useful for identifying peak usage times, detecting unusual traffic spikes, and optimizing resource planning.

Top 10 Destination IP Statistics

  • The “Top 10 Destination IP” statistics display the most frequently accessed or data-receiving destination IP addresses. These insights are vital for network security, performance analysis, and anomaly detection.

Top 10 Source IP Statistics

  • The “Top 10 Source IP” statistics allow users to analyze the IP addresses generating the most traffic or initiating the most connections. This information is crucial for security monitoring, performance tracking, and identifying anomalies.

Top 10 Service Statistics

  • “Top 10 Services” statistics provide an analysis of the most frequently used or highest traffic-generating services in your network. These metrics are essential for verifying security, managing performance, and validating access policies.

Protocol Distribution Statistics

  • The “Protocol Distribution Statistics” feature analyzes the quantity and ratio of protocols used in the network (e.g., TCP, UDP, ICMP). This provides visibility for understanding network behavior and identifying abnormal traffic patterns.

Authorization

  • The Centralized Logging System provides authorization control over data received from Antikor NGFW devices. Authorized users can search within the logs based on their access permissions.

Log Template Management

  • Log Template Management lies at the heart of data collection, configuration, parsing, and reporting within the CLM. It ensures logs from various sources are standardized and made meaningful.

Alert and Notification Monitoring

  • Thresholds defined in Antikor CLM are critical for system continuity. Notifications such as connection losses, re-connections, authorization errors, CPU, disk, and memory spikes are delivered via browser alerts, email, and SMS to inform system administrators.

Encrypted Transfer via SSH Tunnel

  • Data transfer between Antikor NGFW devices and CLM is secured via SSH tunneling, ensuring logs are securely and reliably transmitted. This method is particularly useful for securing unencrypted protocols.

Detailed Audit Logs

  • Antikor CLM provides detailed time-based graphical and tabular reports on traffic, VPN, DNS, application, website, and threat data from connected NGFW sources.

Traffic Analysis

  • Traffic Statistics
  • Displays protocol distribution over time for allowed and blocked traffic. Additionally, tabular data includes source and destination IPs, interface details, and counts of allowed, blocked, and total packets.

Rule Logs

  • Includes hit counts and details for security rules within NGFW sources. It also shows the first and last time each rule was triggered.

VPN Reports

  • Provides time-based charts for the number of VPN users and traffic volume. Tabular reports display user IP addresses, traffic data (bytes sent/received), number of connections, and total connection duration.

Application Logs

  • Shows time-based graphs of allowed and blocked application usage. Tables below display application categories, user counts, and frequency of allowed/blocked actions.

Threat Analysis

  • Graphs threats over time based on severity. Tables list the source, type, score, level, and occurrence count of each detected threat.

Website Logs

  • Presents time-based graphs for allowed and blocked website access. Accompanying tables list session counts and total duration per domain.

DNS Analysis

  • Weekly time-based graphs show top 10 destination and source IP addresses for allowed/blocked DNS queries. Tables display the packet counts for each source and destination in terms of allowed, blocked, and total traffic.

Description

Antikor CLM Centralized Log Management System is a 100% domestic and national product that enables centralized logging with advanced features. With flexible configuration, a live dashboard, and statistical capabilities, it centralizes the logs from all Antikor NGFW devices, allowing users to perform searches across all collected logs from a single point.

It collects logs generated by our Antikor NGFW products and enables reporting based on this data. Reports and charts such as daily session counts, hourly session counts, top 10 targeted IPs, top source IPs, and protocol distribution statistics provide operational insights and benefits to users.

Details and Datasheets: https://www.epati.com.tr/clm