Products
Features
SCALABILITY AND PERFORMANCE
- Cluster server architecture
- ACKLOG can be deployed as either a standalone server or a cluster. Most organizations log ingestion requirements gradually increase in time. Cluster architecture enables users to simply adapt to their changing requirements without having to repeat the installation, configuration, and customization processes.
- Scalable microservices application architecture
- The modern microservices application architecture enables users to bypass bottlenecks in a matter of seconds. Users can optimize their resource utilization by observing and adapting to fluctuating workloads.
- Workload visibility
- SIEM solutions must manage large volumes of log data, so they must optimize their use of underlying resources. We enable users to be aware of the system's load by providing real-time CPU, RAM, disk space utilization, and queue status statistics.
- Monitoring system resource availability
- ACKLOG enables its users to be informed in time with its resource capacity usage alert capability. Users can also use the scheduled alerting capabilities to construct custom alerts to monitor the continuous ingestion of logs from the critical log sources.
- INTUITIVE USER EXPERIENCE
- Visibility of the collected data
- Users must be aware of the data they have access to in order to construct effective queries and alert rules. ACKLOG enables users to view the field names collected from particular nodes as well as all nodes. In addition, the values of specific fields are readily accessible to users.
- Advanced search box and search utilities
- Fieldname and query term completion speeds up the creation of queries. Formatting and highlighting queries improves their readability. Users can save their favorite queries for future use, as well as view and use their previous queries.
- Converting your searches directly into reports, widgets and scheduled alerts
- When it comes to creating reports, widgets, and scheduled alerts, users must be able to visualize the potential outcomes in order to have a better understanding of them. ACKLOG provides its search module as a pivot point to guarantee the user's report, widget, and scheduled alert designs are accurate.
- Easily ingesting custom logs and testing your parsing configuration
- ACKLOG offers no-code parsing capabilities that can parse virtually any log string. Therefore, neither external support nor system updates are required for users to import and parse their custom logs. Users can instantly test the effectiveness of their parsing configuration on raw logs.
- Advanced visualization and dashboard capabilities
- The search module automatically checks to see if the results of a search query can be turned into different kinds of charts. If they can, the user can choose any of those charts to create a widget. ACKLOG's dashboard module lets you make multiple dashboards and play them for different periods of time.
- EFFECTIVE ALERTING AND THREAT HUNTING
- Rich query grammar supporting data transformation and aggregation
- Using massive amounts of log data for threat hunting necessitates robust transformation and aggregation capabilities. ACKLOG provides its users with a rich, flexible, and user-friendly query and aggregation grammar.
- Real time alert capability for fast alerting
- ACKLOG excels when it comes to real-time notification. The real-time alerting infrastructure of ACKLOG processes both indexed and non-indexed data, supports the creation of chain rules to accommodate extremely complex attack detection scenarios, and is scalable like all other ACKLOG services.
- Scheduled alerts for harvesting analytical search capabilities
- While real-time alerting allows for extremely rapid detection of attacks, scheduled alerts are created to maximize the power of aggregated queries. Users can construct extremely complex alert rules to meet their analytical analysis needs at scheduled intervals.
- Utilizing extensive intelligence lists with the matching service
- The size of Threat Intelligence lists is typically large. ACKLOG has a matcher service used to match those lists very quickly with the specified log messages. The matched log messages generate an internal message that can be used in alert mechanisms and/or queried for additional analysis.
- COMPLIANCE AND INVESTIGATION SUPPORT
- Log signature and verification features
- ACKLOG provides assurance regarding the integrity of collected records. Users can use digital signing to satisfy regulatory requirements and establish credibility in the event of an investigation based on the collected logs.
- Exporting and importing logs to satisfy long term retention requirements
- Some regulations and organizational requirements may mandate the long-term retention of records. ACKLOG has log forwarding, snapshotting, and exporting capabilities to facilitate log sharing and long-term retention.
- Various methods for sharing selected logs with third parties
- For users whose clients are heavily regulated or highly sensitive in terms of security monitoring, ACKLOG offers a variety of methods for sharing logs pertinent to these third parties. Users can send parsed and enriched logs directly to third-party systems or share exported log files in bulk.
- Monitoring steady log flow from critical sources
- ACKLOG provides a number of methods for monitoring the healthy flow of log messages from particular log sources. Users can schedule alerts to be notified of any connectivity or other issues that prevent the healthy collection of log messages, or they can view the most recent log ingestion times at any time.
- EASY INSTALLATION, CONFIGURATION AND LICENSING
- Easy installation
- ACKLOG's customized ISO image makes installation easy. During installation of very complex cluster mechanisms, the user is guided with straightforward questions. Even a novice system administrator can install it without error, as the installation procedure is very streamlined.
- Easy configuration
- A multitude of log collection mechanisms are supported by ACKLOG, allowing virtually any type of log data to be ingested. It has simple and intuitive interfaces for adding a new log source, creating a custom logging configuration, checking your parsing configuration's results, and creating alert rules.
- Licensing
- Each organization has distinct requirements and demands for log message processing. We offer a variety of licensing options that correspond to the number of features, resources, and log messages ingested by an organization.
Description
Meet the backbone of your SOC infrastructure Why is ACKLOG an excellent option for your SOC infrastructure backbone? Because it is designed by SOC engineers with a background in offensive security. ACKLOG is designed from the ground up with a highly scalable architecture. It inherits powerful technologies allowing it to scale horizontally and process large amounts of log messages for real time alert creation. Usability is at the hearth of its every function such as easy parsing configuration, directly converting search results into reports, scheduled alerts and dashboard widgets, a search box with keyword highlighting and field name completion, a great grammar allowing the users to create analytical queries easily, etc.
