Another Data Center Headache: Log Data Exploding

The newest storage headache for data centers? A worsening torrent of real-time log data. Bad news: For compliance reasons, you'll soon have to not only store more log data, but also make it more searchable. Good news: You can use this data to improve security.

By Robert Lemos

CONNECTIONS
The 451 Group
Hewlett-Packard
SenSage
Wed, April 29, 2009CIO Following the March, 2004, bombings in Madrid, Spain, law enforcement searching for leads on those responsible for the attacks focused on the cell phones used by the terrorists and requested that European telecommunications providers turn over their call data. The only problem: It took the companies weeks to find the relevant data.

In attempt to eliminate such problems in the future, the European Union created data-retention guidelines that require service providers to hold up to two years worth of call records and Internet records. The amount of data that the companies have to store skyrocketed—becoming a major data center issue.

"One of the issues is the volume of data," says Matthew Aslett, enterprise software analyst for The 451 Group. "One European telco we have spoken to cited three years of data equating to 36TB of storage."

The storage problem reaches far beyond Europe. While most companies use data centers to store their primary business information—such as backups of important files and customer data—real-time log data and unstructured transactional data are quickly becoming major issues as well, according to Aslett and other experts.

Most industries will face a significant data problem in the future, as compliance requirements force them to not only retain more data, but also make such data easily searchable.

Banks have to keep data from cash machines, utilities have to keep data on various events happening on their control and monitoring networks, and public companies need to document who accessed certain sensitive financial data to be compliant with Sarbanes-Oxley.

Much of the data is stored as event logs from a host of different devices on a network.

In the past, event data was not stored in a way to make retrieval easy. Every device on a network—whether a bank's ATM network, a corporate local network or a utility's control network—generates event data and storing that data has always been a problem. The issues will only become more significant in the future.

"Clearly some of the major drivers are SOX and PCI (requirements), for which security log management is a partial answer to the problem, but issues such as the EU data retention guidelines for electronic communications are potentially broader and larger problems in terms of the amount of data to be collected and analyzed," he says.

Hewlett-Packard, one of many companies that sells systems to handle so-called event data warehousing issues, sees customers dealing with anywhere from 10 GB of data per day to 1 TB of data daily.

"There is a torrent of information coming out of these devices," says Gary Lefkowitz, a director in HP's Secure Advantage group.

Yet, once collected, the data becomes and opportunity for the company, he says. "A lot of customers look at this as a compliance tax, but once you get your system running, it is not like you are just checking off the compliance box—there are a whole host of things you can do."

Companies that store such event data in a easily accessible way, for example, find that they can analyze the data for anomalous events that could indicate an attacker in their system, says Jim Pflaging, CEO of data-warehousing software provider SenSage.

"We think there is a class of customers that will really see this as a positive thing for the security of their company," he says. "To nail insiders, you really have to collect more data. Insiders don't have failed logins—you have to be able to analyze how they accessed the data."

In the past, companies that collected log data in a single location would typically use a flat file, which made the data difficult to comb through for significant events, says Pflaging. Using more efficient database software to store and retrieve the data, companies also gain a lot more insight into what is happening amongst the devices on their network, he says.

"For most companies, this security log data will be the largest single data store," Pflaging says.

Follow everything from CIO.com on Twitter @CIOonline

storage

Loading...
Data Center MarketSpace
IT Consolidation Made Easy
The Primary IT Initiative for Reducing Costs Learn more »
Data Center Cost Analysis
Read this white paper to see how a server refresh can actually save money and meet green initiatives. Learn more »
The Future Data Center
Building the next-generation data center requires a forward-thinking strategy that encompasses a broad range of new technologies. Learn more »
Cutting the Cost of Enterprise Databases
This IDC white paper discusses the growing complexity of datacenter management, which is causing escalating costs. Learn more »
8 Tactics to Combat Vulnerabilities
This white paper reviews 8 key elements of vulnerability management and provides advice on combating known vs. unknown vulnerabilities. Learn more »
Lower IT Costs with Oracle Database 11g Release 2
Learn how upgrading to Oracle Database 11g Release 2 can transform your business, budgets, and service levels Learn more »
An Alternative Database Approach
Learn how a column-oriented DBMS works, why it has superior performance, reduced data access latency and a reduced storage footprint. Learn more »
 
SPONSORED LINKS
 

White Paper: Right-Sizing Your Power Infrastructure

Lower IT Costs with Oracle Database 11g Release 2

New technology that addresses challenges organizations are facing.

White Paper: 4 Customer Service Myths

White Paper: Managed Security for a Not-So-Secure World

White Paper: 5 Best Practices for Smartphone Support

Global Research: CIOs Weigh In On Virtualization

5 Key Virtualization Management Challenges

Secure Email and Web-Based Communication from Evolving Attacks

WagerWorks Takes Fraudsters Out of the Game using iovation

Seven Design Requirements for Web 2.0 Threat Protection

Generation Remote Infrastructure Management - Changing the Paradigm

Cloud-Based Email Management: Opinion Shifts In Favor

eBook: How Can You Make Your People Productive Anywhere?

White Paper: Visibility and the New Normal of Mobile Work

Taking the Service Desk to the Next Level

Learn about The Information Technology Infrastructure Library.

Top Five CIO Challenges

Streamline IT Costs. Boost Performance with WAN Optimization.

Want to know how you can maximize employee productivity?

Build your 1st app FREE with Force.com

TDWI checklist helps define data readiness for analytics. Download report.

A new fleet of PCs with a total ROI in 10 months. Find your ROI.

eZine: A Roadmap to Reducing IT Complexity

Reduce risk, gain agility. See how Progress can help your business.

State of the Data Integration Market

Server Consolidation: Leveraging the Benefits of Virtualization

See how AT&T can help protect your network.

Webcast: Unleashing the Power of Customer Data

White Paper: Improve Agility with Operational Responsiveness

White Paper: Legacy Tools: Not Built for the Helpdesk

Taking a Seat at the Executive Table: The Reality of Virtualization

White Paper: Next Generation Remote Infrastructure Management

Keeping Your Members Safe from Online Scams and Predators

The Total Economic Impact of Network Security Intrusion Prevention

Join us at the US-Brazil IT-BPO Summit, on November 10th in New York.

Increase UPS efficiency without sacrificing protection.

Learn how advanced forecasting tools can deliver significant business results for global corporations.

Achieving Business Agility with Application Grid

Ready to virtualize tier one applications? Check your virtualization maturity.

Seven Ways ITIL Can Help You in an Economic Downturn

Tips for successful virtualization management.

Unified Communications: Thoughts, Strategies and Predictions. Join the discussion

Read the RSA report: Security for Business Innovation

Webcast: Looking to the Cloud for Email and Collaboration Services

64-page prescriptive guide to security, compliance, and IT operations.

Keep your IT expertise up to date. Join the Intel Premier IT Professionals.

A Clear View Toward Virtualization

Virtualization Technology as a Business Solution

The rules of infrastructure management just changed.

 
 
RESOURCE CENTER