SlideShare a Scribd company logo
Have you planned your
                                         replacement for Cisco MARS?


© 2013, SolarWinds Worldwide, LLC. All rights reserved.

                                                          1
Agenda

1. Why should you find a replacement now?
2. What to look for in a replacement tool?
3. Why SolarWinds could be the right alternative
        a.     Deployment
        b.     Event Correlation
        c.     Power of Search
        d.     Compliance Reporting
        e.     Incident Response
        f.     Device Support
4. Additional Security Recommendations




CISCO MARS REPLACEMENT- SOLARWINDS LEM
                                         2
Why should find a replacement now?

»       What’s up with Cisco MARS?

       Cisco has decided it is right time for
        the hardware to not be sold in the
        market and it has been scrapped for
        new purchases                            Do you have a plan B?
       Cisco no longer sells Cisco Security     We have one for you…
        Monitoring, Analysis and Response
                                                 Check how SolarWinds Log and
        System (MARS)                            Event Manager (LEM) can help?
       Read the End-of-Life Notice to learn
        more




    CISCO MARS REPLACEMENT- SOLARWINDS LEM
                                             3
What to look for in a replacement tool?

»      Best-in-class SIEM technology provides:
       All-in-one affordable log and event analysis
       Active responses to react to real-time threats while complying with
        regulatory policies

»       Also a SIEM tool that has in-memory analytics that can capture, correlate
        and respond to network attacks and insider abuse at network speed.




CISCO MARS REPLACEMENT- SOLARWINDS LEM
                                          4
Why SolarWinds could be your alternative

Let us consider the top 6 decisive factors:
   1. Deployment
   2. Event-Correlation functionality
   3. Power of Search
   4. Compliance Reporting
   5. Incident Response
   6. Device Support

»       See how SolarWinds Log and Event Manager (LEM) compares to Cisco
        MARS on all the above parameters.




CISCO MARS REPLACEMENT- SOLARWINDS LEM
                                         5
Deployment

» Cisco MARS                                 » SolarWinds LEM
    It is a hardware appliance which           Its a virtual appliance which
     requires physical setup and                 downloads and deploys in just
     network connections to become               under an hour.
     fully operational.

    It is not a standalone solution,           LEM is all equipped own its
     but part of Cisco Security                  own and needs no supporting
     Management Suite which needs                and add-on devices or modules
     the support of Cisco Security               to deliver its full service.
     Manager (CSM) to deliver the
     full extent of service.




CISCO MARS REPLACEMENT- SOLARWINDS LEM
                                         6
Event Correlation

» Cisco MARS                                   » SolarWinds LEM
       It comes with the complexity of           As a standalone product, uses
        defining      and     building             its         multi-dimensional
        correlation rules to handle                correlation engine to detect
        multiple device and multiple               behavioral anomalies in real-
        events                                     time.
       Relies on Cisco CSM to perform            It also employs a simple and
        event correlation                          easy-to-use rule builder with
                                                   familiar drag and drop
                                                   interface, icon-based tool
                                                   panel and graphical object
                                                   selection panel.

  LEM also comes with 700+ pre-built correlation rules that cover critical network
  infrastructure, change management and network security functions.
CISCO MARS REPLACEMENT- SOLARWINDS LEM
                                           7
Event Correlation (Contd…)

»       SolarWinds LEM can:
       Correlate time-based and transaction-
        based events
       Send notifications and trigger actions
        based on event correlation that
        happens in-memory
       Perform multiple event correlation
       Ability to set independent thresholds
        for activity per event, or group of
        events
       Leverage non-linear event correlation
       Access to field-level data for event     LEM’s Correlation Rule Builder Interface with Simple Drag &
                                                 Drop Options
        correlation rules
       Create user-defined groups and
        variables for event correlation rules

CISCO MARS REPLACEMENT- SOLARWINDS LEM
                                            8
Power of Search

» Cisco MARS                                          » SolarWinds LEM
       The scope of search in MARS is                   LEM is equipped with a powerful
        basic and limited                                 and intuitive search option with
                                                          which you can explore search log
       The method of search is not                       data visually.
        very simple
                                                         It also allows you to use search
                                                          tools like Word Clouds, Tree-
                                                          maps, Bubble Charts and
                                                          Histograms.



                                   Notable here is the Word Clouds -
                       the first implementation ever in a log monitoring system.

CISCO MARS REPLACEMENT- SOLARWINDS LEM
                                                  9
Power of Search (Contd…)

»      Not just search, LEM allows you to
       store log data in a centralized
       repository.

»      Compares original log data and
       normalized event data side-by-side
       and     easily found with LEM’s
       various search options.

»      Eliminates the need for additional
       hardware with a high compression
       data model that stores data at up
       to a 60:1 compression ratio.               LEM’s Advanced & Intuitive IT Search Options




    CISCO MARS REPLACEMENT- SOLARWINDS LEM
                                             10
Compliance Reporting

»     LEM comes with 300+ "audit-
      proven" compliance reports to
      comply with so many federal
      policies like PCI DSS, GLBA, SOX,
      NERC CIP, HIPAA and even more.

»     You can run these policies
      through LEM to get graphical
      report summaries from the
      extensive resource of log data
      that were captured in real-time.

»     Cisco MARS is not equipped with
                                             Select Your Choice of Regulatory Compliance Policies and Run Reports Using LEM
      such a store of compliance
      reports




    CISCO MARS REPLACEMENT- SOLARWINDS LEM
                                                       11
Incident Response

»     With a library of built-in Active Responses LEM
      executes the automated responses needed to
      mitigate threats and respond to operational
      issues, security breaches, malware and policy
      violations immediately.

»     LEM doesn’t need any integration with any
      Incident Response system.

»     Whereas Cisco MARS which requires
      integration with Cisco Intrusion Prevention
      System (IPS) to respond and take action on             LEM’s Active Response Technology in Action
      real-time security threats.



    Some of LEM’s Active Responses include quarantining infected machines, blocking IP
    addresses, disabling user accounts, killing unauthorized processes and restarting services.



    CISCO MARS REPLACEMENT- SOLARWINDS LEM
                                                        12
Device Support

»       MARS is focused on Cisco networking devices
»       SolarWinds LEM extends support to network devices from dozens of
        manufacturers, hundreds of products, and thousands of models and
        various operating systems and applications.




                                         Supports Multiple Devices
CISCO MARS REPLACEMENT- SOLARWINDS LEM
                                                           13
Test Drive an Alternative for MARS

»       SolarWinds’ best-in-class SIEM technology provides all-in-one affordable
        log and event analysis and management software that also performs
        active responses to react to real-time threats while complying with
        regulatory policies.




         Try out the fully-functional 30-day free trial to see LEM in action.

CISCO MARS REPLACEMENT- SOLARWINDS LEM
                                         14
Additional Security Recommendations

»      Some other key areas that you may need to equip yourself are:
           Firewall Security Management
           Network Change & Configuration Management
           Endpoint Vulnerability Management
           Endpoint Data Loss Preventions



»      You can read more from this whitepaper
       The Case for Security Information and
       Event Management (SIEM) in Proactive
       Network Defense




    CISCO MARS REPLACEMENT- SOLARWINDS LEM
                                             15
Thank You!




CISCO MARS REPLACEMENT- SOLARWINDS LEM
                                         16

More Related Content

PDF
IT Security Risk Mitigation Report: Virtualization Security
KEY
Cloudop security
PDF
HyTrust and VMware-Providing a Secure Virtual Infrastructure
PPTX
Secure Your Virtualized Environment. Protection from Advanced Persistent Thre...
PDF
Cloud Security: Perception VS Reality
PDF
Transitioning to Next-Generation Firewall Management - 3 Ways to Accelerate t...
PPTX
HCI ECOCAST
PDF
UShareSoft Virtualization & Cloud Factory
IT Security Risk Mitigation Report: Virtualization Security
Cloudop security
HyTrust and VMware-Providing a Secure Virtual Infrastructure
Secure Your Virtualized Environment. Protection from Advanced Persistent Thre...
Cloud Security: Perception VS Reality
Transitioning to Next-Generation Firewall Management - 3 Ways to Accelerate t...
HCI ECOCAST
UShareSoft Virtualization & Cloud Factory

Similar to What is your alternative to Cisco MARS? (20)

PPT
SolarWinds Log & Event Manager vs Splunk. What's the Difference?
PPTX
CLOUD NATIVE SECURITY
PPT
How-To: Linux Performance Monitoring & Management for your Multi-Vendor Network
DOCX
Overall Security Process Review CISC 6621Agend.docx
PPTX
Setting up a secure development life cycle with OWASP - seba deleersnyder
PDF
Elastic SIEM (Endpoint Security)
PDF
BMC - Response to the SolarWinds Breach/Malware
PPTX
McAfee - Enterprise Security Manager (ESM) - SIEM
PDF
ClearArmor CSRP - 01.01 SOFTWARE BASED VULNERABILITIES
PDF
5-Ways-To-Future-Proof-Your-SIEM-Securonix[1].pdf
PPTX
The Future of Embedded and IoT Security: Kaspersky Operating System
PDF
Cloud Security - Made simple
PPTX
ManageEngine_SIEM_Log360_SOC.pptx
PPTX
Security Information Event Management - nullhyd
PDF
Reactive Architecture
PDF
Glenn Lazarus- Why Your Observability Strategy Needs Security Observability
PPTX
the_role_of_resilience_data_in_ensuring_cloud_security.pptx
PDF
the_role_of_resilience_data_in_ensuring_cloud_security.pdf
PDF
Tenable Solutions for Enterprise Cloud Security
PDF
Symantec Best Practices for Cloud Security: Insights from the Front Lines
SolarWinds Log & Event Manager vs Splunk. What's the Difference?
CLOUD NATIVE SECURITY
How-To: Linux Performance Monitoring & Management for your Multi-Vendor Network
Overall Security Process Review CISC 6621Agend.docx
Setting up a secure development life cycle with OWASP - seba deleersnyder
Elastic SIEM (Endpoint Security)
BMC - Response to the SolarWinds Breach/Malware
McAfee - Enterprise Security Manager (ESM) - SIEM
ClearArmor CSRP - 01.01 SOFTWARE BASED VULNERABILITIES
5-Ways-To-Future-Proof-Your-SIEM-Securonix[1].pdf
The Future of Embedded and IoT Security: Kaspersky Operating System
Cloud Security - Made simple
ManageEngine_SIEM_Log360_SOC.pptx
Security Information Event Management - nullhyd
Reactive Architecture
Glenn Lazarus- Why Your Observability Strategy Needs Security Observability
the_role_of_resilience_data_in_ensuring_cloud_security.pptx
the_role_of_resilience_data_in_ensuring_cloud_security.pdf
Tenable Solutions for Enterprise Cloud Security
Symantec Best Practices for Cloud Security: Insights from the Front Lines
Ad

More from SolarWinds (20)

PPTX
SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...
PPTX
SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...
PPTX
Government Webinar: Alerting and Reporting in the Age of Observability
PPTX
Government and Education Webinar: Full Stack Observability
PPTX
Government and Education Webinar: Public Sector Cybersecurity Survey - What I...
PPTX
Becoming Secure By Design: Questions You Should Ask Your Software Vendors
PPTX
Government and Education Webinar: Real-Time Mission, CIO, and Command Dashboards
PPTX
Government and Education Webinar: Simplify Your Database Performance Manageme...
PPTX
Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...
PPTX
Government and Education Webinar: Leverage Automation to Improve IT Operations
PPTX
Government and Education Webinar: Improving Application Performance
PPTX
Government and Education: IT Tools to Support Your Hybrid Workforce
PPTX
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
PPTX
SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...
PPTX
Government and Education Webinar: Zero-Trust Panel Discussion
PPTX
Government and Education: Leveraging The SolarWinds Orion Assistance Program ...
PPTX
Government and Education Webinar: SQL Server—Advanced Performance Tuning
PPTX
Government and Education Webinar: Recovering IP Addresses on Your Network
PPTX
Government and Education Webinar: Optimize Performance With Advanced Host Mon...
PPTX
Government and Education Webinar: Conquering Remote Work IT Challenges
SolarWinds Government and Education Webinar: Greatest SolarWinds Features I N...
SolarWinds Government and Education Webinar: Gaps Exist in Your Monitoring In...
Government Webinar: Alerting and Reporting in the Age of Observability
Government and Education Webinar: Full Stack Observability
Government and Education Webinar: Public Sector Cybersecurity Survey - What I...
Becoming Secure By Design: Questions You Should Ask Your Software Vendors
Government and Education Webinar: Real-Time Mission, CIO, and Command Dashboards
Government and Education Webinar: Simplify Your Database Performance Manageme...
Government and Education Webinar: SolarWinds Orion Platform: Audit and Stream...
Government and Education Webinar: Leverage Automation to Improve IT Operations
Government and Education Webinar: Improving Application Performance
Government and Education: IT Tools to Support Your Hybrid Workforce
Government and Education Webinar: There's More Than One Way to Monitor SQL Da...
SolarWinds Government and Education Webinar: Virtual Technology Briefing 08.0...
Government and Education Webinar: Zero-Trust Panel Discussion
Government and Education: Leveraging The SolarWinds Orion Assistance Program ...
Government and Education Webinar: SQL Server—Advanced Performance Tuning
Government and Education Webinar: Recovering IP Addresses on Your Network
Government and Education Webinar: Optimize Performance With Advanced Host Mon...
Government and Education Webinar: Conquering Remote Work IT Challenges
Ad

Recently uploaded (20)

PDF
Approach and Philosophy of On baking technology
PDF
Electronic commerce courselecture one. Pdf
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Encapsulation_ Review paper, used for researhc scholars
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Assigned Numbers - 2025 - Bluetooth® Document
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PPTX
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PDF
Network Security Unit 5.pdf for BCA BBA.
PPTX
A Presentation on Artificial Intelligence
PPT
Teaching material agriculture food technology
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
Empathic Computing: Creating Shared Understanding
Approach and Philosophy of On baking technology
Electronic commerce courselecture one. Pdf
Spectral efficient network and resource selection model in 5G networks
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
“AI and Expert System Decision Support & Business Intelligence Systems”
Encapsulation_ Review paper, used for researhc scholars
20250228 LYD VKU AI Blended-Learning.pptx
Advanced methodologies resolving dimensionality complications for autism neur...
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
MYSQL Presentation for SQL database connectivity
Assigned Numbers - 2025 - Bluetooth® Document
Diabetes mellitus diagnosis method based random forest with bat algorithm
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
Network Security Unit 5.pdf for BCA BBA.
A Presentation on Artificial Intelligence
Teaching material agriculture food technology
The Rise and Fall of 3GPP – Time for a Sabbatical?
Empathic Computing: Creating Shared Understanding

What is your alternative to Cisco MARS?

  • 1. Have you planned your replacement for Cisco MARS? © 2013, SolarWinds Worldwide, LLC. All rights reserved. 1
  • 2. Agenda 1. Why should you find a replacement now? 2. What to look for in a replacement tool? 3. Why SolarWinds could be the right alternative a. Deployment b. Event Correlation c. Power of Search d. Compliance Reporting e. Incident Response f. Device Support 4. Additional Security Recommendations CISCO MARS REPLACEMENT- SOLARWINDS LEM 2
  • 3. Why should find a replacement now? » What’s up with Cisco MARS?  Cisco has decided it is right time for the hardware to not be sold in the market and it has been scrapped for new purchases Do you have a plan B?  Cisco no longer sells Cisco Security We have one for you… Monitoring, Analysis and Response Check how SolarWinds Log and System (MARS) Event Manager (LEM) can help?  Read the End-of-Life Notice to learn more CISCO MARS REPLACEMENT- SOLARWINDS LEM 3
  • 4. What to look for in a replacement tool? » Best-in-class SIEM technology provides:  All-in-one affordable log and event analysis  Active responses to react to real-time threats while complying with regulatory policies » Also a SIEM tool that has in-memory analytics that can capture, correlate and respond to network attacks and insider abuse at network speed. CISCO MARS REPLACEMENT- SOLARWINDS LEM 4
  • 5. Why SolarWinds could be your alternative Let us consider the top 6 decisive factors: 1. Deployment 2. Event-Correlation functionality 3. Power of Search 4. Compliance Reporting 5. Incident Response 6. Device Support » See how SolarWinds Log and Event Manager (LEM) compares to Cisco MARS on all the above parameters. CISCO MARS REPLACEMENT- SOLARWINDS LEM 5
  • 6. Deployment » Cisco MARS » SolarWinds LEM  It is a hardware appliance which  Its a virtual appliance which requires physical setup and downloads and deploys in just network connections to become under an hour. fully operational.  It is not a standalone solution,  LEM is all equipped own its but part of Cisco Security own and needs no supporting Management Suite which needs and add-on devices or modules the support of Cisco Security to deliver its full service. Manager (CSM) to deliver the full extent of service. CISCO MARS REPLACEMENT- SOLARWINDS LEM 6
  • 7. Event Correlation » Cisco MARS » SolarWinds LEM  It comes with the complexity of  As a standalone product, uses defining and building its multi-dimensional correlation rules to handle correlation engine to detect multiple device and multiple behavioral anomalies in real- events time.  Relies on Cisco CSM to perform  It also employs a simple and event correlation easy-to-use rule builder with familiar drag and drop interface, icon-based tool panel and graphical object selection panel. LEM also comes with 700+ pre-built correlation rules that cover critical network infrastructure, change management and network security functions. CISCO MARS REPLACEMENT- SOLARWINDS LEM 7
  • 8. Event Correlation (Contd…) » SolarWinds LEM can:  Correlate time-based and transaction- based events  Send notifications and trigger actions based on event correlation that happens in-memory  Perform multiple event correlation  Ability to set independent thresholds for activity per event, or group of events  Leverage non-linear event correlation  Access to field-level data for event LEM’s Correlation Rule Builder Interface with Simple Drag & Drop Options correlation rules  Create user-defined groups and variables for event correlation rules CISCO MARS REPLACEMENT- SOLARWINDS LEM 8
  • 9. Power of Search » Cisco MARS » SolarWinds LEM  The scope of search in MARS is  LEM is equipped with a powerful basic and limited and intuitive search option with which you can explore search log  The method of search is not data visually. very simple  It also allows you to use search tools like Word Clouds, Tree- maps, Bubble Charts and Histograms. Notable here is the Word Clouds - the first implementation ever in a log monitoring system. CISCO MARS REPLACEMENT- SOLARWINDS LEM 9
  • 10. Power of Search (Contd…) » Not just search, LEM allows you to store log data in a centralized repository. » Compares original log data and normalized event data side-by-side and easily found with LEM’s various search options. » Eliminates the need for additional hardware with a high compression data model that stores data at up to a 60:1 compression ratio. LEM’s Advanced & Intuitive IT Search Options CISCO MARS REPLACEMENT- SOLARWINDS LEM 10
  • 11. Compliance Reporting » LEM comes with 300+ "audit- proven" compliance reports to comply with so many federal policies like PCI DSS, GLBA, SOX, NERC CIP, HIPAA and even more. » You can run these policies through LEM to get graphical report summaries from the extensive resource of log data that were captured in real-time. » Cisco MARS is not equipped with Select Your Choice of Regulatory Compliance Policies and Run Reports Using LEM such a store of compliance reports CISCO MARS REPLACEMENT- SOLARWINDS LEM 11
  • 12. Incident Response » With a library of built-in Active Responses LEM executes the automated responses needed to mitigate threats and respond to operational issues, security breaches, malware and policy violations immediately. » LEM doesn’t need any integration with any Incident Response system. » Whereas Cisco MARS which requires integration with Cisco Intrusion Prevention System (IPS) to respond and take action on LEM’s Active Response Technology in Action real-time security threats. Some of LEM’s Active Responses include quarantining infected machines, blocking IP addresses, disabling user accounts, killing unauthorized processes and restarting services. CISCO MARS REPLACEMENT- SOLARWINDS LEM 12
  • 13. Device Support » MARS is focused on Cisco networking devices » SolarWinds LEM extends support to network devices from dozens of manufacturers, hundreds of products, and thousands of models and various operating systems and applications. Supports Multiple Devices CISCO MARS REPLACEMENT- SOLARWINDS LEM 13
  • 14. Test Drive an Alternative for MARS » SolarWinds’ best-in-class SIEM technology provides all-in-one affordable log and event analysis and management software that also performs active responses to react to real-time threats while complying with regulatory policies. Try out the fully-functional 30-day free trial to see LEM in action. CISCO MARS REPLACEMENT- SOLARWINDS LEM 14
  • 15. Additional Security Recommendations » Some other key areas that you may need to equip yourself are:  Firewall Security Management  Network Change & Configuration Management  Endpoint Vulnerability Management  Endpoint Data Loss Preventions » You can read more from this whitepaper The Case for Security Information and Event Management (SIEM) in Proactive Network Defense CISCO MARS REPLACEMENT- SOLARWINDS LEM 15
  • 16. Thank You! CISCO MARS REPLACEMENT- SOLARWINDS LEM 16