Lancope StealthWatch Management Console 2000 - Network management device - AC 100/230 V - 1U - Refresh Program - rack-mountable
- Insightful real-time reporting
- Efficient centralized administration across distributed enterprise deployments
- Customizable and flexible graphical visualization of security and network events and behavior
- Drill-down analysis of security and network events
- Point-of-View technology
- Integrated internal and external monitoring
Armed with graphical representations of network traffic, customized summary reports, and integrated security and network intelligence for drill-down analysis, administrators can easily identify internal and external attacks, network exposures and policy violations. The StealthWatch Management Console also enhances network management through trend analysis, firewall and capacity planning, interdepartmental billing and performance monitoring.
The StealthWatch Management Console (SMC) manages, coordinates and configures StealthWatch appliances and flow collectors (NetFlow, IPFIX, sFlow) to correlate security and network intelligence from StealthWatch components deployed at critical segments throughout the enterprise. This ability to delivers real-time insight into current network behavior increases network and security team efficiency and decreases operating costs, while simultaneously improving overall security posture and operational awareness.
Featuring Java-based platform independence, the SMC enables instant data correlation, traffic visualization and consolidated reporting. Administrators can detect and prioritize security threats, pinpoint network misuse and suboptimal performance, and manage incident response across the enterprise - all from a single control center.
-
Insightful real-time reporting
The StealthWatch Management Console provides valuable insight into network usage via pre-defined, customizable XML-based reports that include source/destination IP address, services, time period, traffic protocol and bandwidth levels. Administrators use this information to perform essential security and network management tasks, such as creating and assessing security policies; ensuring proper configuration of firewalls, servers and other network devices; and identifying trends in order to anticipate and remedy potential problems.
-
Efficient centralized administration across distributed enterprise deployments
The SMC simplifies remote administration for multiple StealthWatch sensors and collectors regardless of physical location. Administrators centrally define and implement hierarchical security zones, security and network usage policies and various appliance configuration parameters. Low bandwidth transmissions between StealthWatch appliances and the SMC maximize performance with minimal impact on normal network operations. In addition, the SMC provides streamlined integration between the StealthWatch System and standard network management applications.
-
Customizable and flexible graphical visualization of security and network events and behavior
Advanced graphics and customizable preferred views of network activity deliver unique insight into the security and usage of the network. Graphical displays of network traffic relationships and security intelligence help network and security teams understand traffic patterns and identify deviations from normal network behavior. This visualization aids the detection of Denial of Service (Dos) and distributed Denial of Service attacks, worms, pre-attack reconnaissance and network misuse. The StealthWatch Management Console also helps administrators identify network bottlenecks, spot malfunctioning network devices and perform capacity planning to optimize network performance.
-
Drill-down analysis of security and network events
The StealthWatch Management Console correlates data across the enterprise for in-depth, root-cause analysis and rapid recognition of network and security trends. Drill-down analysis into alarms, host-level activity and suspicious network behavior enables administrators to quickly prioritize and respond to contain attacks and mitigate network damage. The console's user-friendly UI intuitively guides administrators through the various layers of information provided by StealthWatch appliances across the network.
-
Point-of-View technology
StealthWatch proves equally valuable for network and security engineers. Point-of-View technology within the StealthWatch Management Console provides a unique, customized view of the network for each IT role. Network engineers see router interface statistics, top talkers and trending reports. Security analysts receive reports detailing policy violations, worm outbreaks and other malware traversing the network. StealthWatch Point-of-View technology brings flow-based analysis benefits to the entire IT organization.
-
Integrated internal and external monitoring
The StealthWatch Management Console employs a high-speed customizable syslog parser to facilitate integration with other network and security technologies such as firewalls, IDS/IPS appliances and any other technology capable of exporting syslog messages. As events are received from external systems, they are decoded, correlated with StealthWatch events and stored for later analysis in the StealthWatch Management Console database.