CNEye
Splunk-based security monitoring solution
Splunk-based security monitoring solution
CN-Eye is a monitoring solution developed by CloudNetworks based on the big data platform Splunk Enterprise.
It works in conjunction with Citrix and HashiCorp solutions.
CNEye is an integrated internal information leakage management system that analyzes various system-generated risk signs in combination with user behavior and scenarios based on the big data analysis platform Splunk. It provides a comprehensive risk sign management system through pre-analysis, cause identification and intensive analysis, and clarification procedures.
It detects abnormal signs through various scenario-based event rulesets by collecting internal security equipment and work system logs.
Internal personnel DB is easily integrated into the company's infrastructure through linkage with the mail server to provide a reporting process.
Dashboard configuration that can monitor the status of the entire system by integrating linked system data and monitor the risk level by department/branch, etc.
Dashboard configuration for monitoring by event for abnormal behavior and major activities, and report and monitoring dashboard configuration using flexible visualization tools
Analysis of abnormal behavior, misuse and insider information leakage based on scenario, timeline analysis of usage patterns and overall status of events by user
If a user is deemed to be behaving abnormally through user analysis, management is carried out through an explanation process, and it can be processed by specifying an example and user.
CNEye For Citrix is a monitoring solution for CITRIX ADC products. It provides easy asset management and real-time information collection, analysis, and event and integrated dashboard functions based on an intuitive UI, making it convenient to use.
CNEye for Vault is a cloud security automation monitoring solution that can be linked and analyzed with HashicCorp Vault for secret management. It allows convenient operation and management from a security perspective with a visual dashboard for Vault configuration and various metrics.
Provides an integrated dashboard according to the configuration of Vault, enabling you to understand Vault from an operational and security perspective and build your own visualizations according to the configuration
Smooth cluster management by checking the cluster status and the mode of each node
Pre-manage by setting license expiration dates and D-Day, and check the total number of entities
Visualization of key items from an operational perspective, such as Auth, Secret, Token, Policy, and Resource (CPU/Memory/Disk), to identify abnormal patterns
Check in the form of a message table of Warm/Error levels, Receive alarms via Slack integration