<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-6690994337395244641.post5715721665931898579..comments</id><updated>2007-03-29T16:02:42.749-05:00</updated><title type='text'>Comments on Paul Melson's Blog: Me vs. Mike Rothman: Could I Possibly Win?</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://pmelson.blogspot.com/feeds/5715721665931898579/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6690994337395244641/5715721665931898579/comments/default'/><link rel='alternate' type='text/html' href='http://pmelson.blogspot.com/2007/03/me-vs-mike-rothman-could-i-possibly-win.html'/><author><name>PaulM</name><uri>http://www.blogger.com/profile/02530533566781746778</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>2</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6690994337395244641.post-7740415149913671813</id><published>2007-03-29T16:02:00.000-05:00</published><updated>2007-03-29T16:02:00.000-05:00</updated><title type='text'>"SIM can be useful for incident response, BUT ONLY...</title><content type='html'>&lt;B&gt;&lt;I&gt;"SIM can be useful for incident response, BUT ONLY IF YOU DON'T MESS WITH THE RECORDS. Any kind of normalization, data reduction or anything else is a no-no. You mess with the data, it ceases to be evidence."&lt;/B&gt;&lt;/I&gt;&lt;BR/&gt;&lt;BR/&gt;If you want evidence to be "court-ready," then having access to the originals is necessary.  But chomping logs - or more accurately, copies of logs -  and inserting them into a database doesn't render them useless.  Far from it.  But maybe we're missing eachother on semantics here.  For instance, from my SIM console I can open a single IDS alert and view the original payload in hex or ascii.  So maybe it's all about depth of features. &lt;BR/&gt;&lt;BR/&gt;My point, in case I buried it in my original rebuttal of your article, is that SIM can streamline incident response and investigation by putting lots of data from different platforms and sources in one place where it can be searched and compared.  But also, your company's log data and operating environment are different enough that you can't buy a SIM that will find all the jewels and only jewels without some work on your part.&lt;BR/&gt;&lt;BR/&gt;And I enjoy very much the dialog on this topic.  Let's do it again some time.  :-)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6690994337395244641/5715721665931898579/comments/default/7740415149913671813'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6690994337395244641/5715721665931898579/comments/default/7740415149913671813'/><link rel='alternate' type='text/html' href='http://pmelson.blogspot.com/2007/03/me-vs-mike-rothman-could-i-possibly-win.html?showComment=1175202120000#c7740415149913671813' title=''/><author><name>PaulM</name><uri>http://www.blogger.com/profile/02530533566781746778</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='07710546765367697106'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://pmelson.blogspot.com/2007/03/me-vs-mike-rothman-could-i-possibly-win.html' ref='tag:blogger.com,1999:blog-6690994337395244641.post-5715721665931898579' source='http://www.blogger.com/feeds/6690994337395244641/posts/default/5715721665931898579' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-6690994337395244641.post-6384974433916131719</id><published>2007-03-28T09:55:00.000-05:00</published><updated>2007-03-28T09:55:00.000-05:00</updated><title type='text'>I don't know any Mr. Rothman. Folks just call me M...</title><content type='html'>I don't know any Mr. Rothman. Folks just call me Mike. :-)&lt;BR/&gt;&lt;BR/&gt;Thanks for the comments and the dialog. In a roundabout way, you validated the point I am making about SIM. It doesn't solve the customers problem. At least not the problem that the folks that sell the solution think it does.&lt;BR/&gt;&lt;BR/&gt;And most SIM packages mess with the log data. That's a no-no when you are undertaking an investigation. To me that's the difference between a log management offering and a SIM.&lt;BR/&gt;&lt;BR/&gt;Paul, it's not about winning or losing. It's about having a good dialog.&lt;BR/&gt;&lt;BR/&gt;Mike.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6690994337395244641/5715721665931898579/comments/default/6384974433916131719'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6690994337395244641/5715721665931898579/comments/default/6384974433916131719'/><link rel='alternate' type='text/html' href='http://pmelson.blogspot.com/2007/03/me-vs-mike-rothman-could-i-possibly-win.html?showComment=1175093700000#c6384974433916131719' title=''/><author><name>Mike Rothman</name><uri>http://blog.securityincite.com</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://pmelson.blogspot.com/2007/03/me-vs-mike-rothman-could-i-possibly-win.html' ref='tag:blogger.com,1999:blog-6690994337395244641.post-5715721665931898579' source='http://www.blogger.com/feeds/6690994337395244641/posts/default/5715721665931898579' type='text/html'/></entry></feed>