Overview
SPiDER TM is a SIEM(Security Information & Event Management) solution with 20 years of experience of Managed Security Services and Big data capabilities from IGLOO Corporation. It can enhance agility and efficiency of security monitoring services through centralized monitoring environment structure from initial detection to log/network packet analysis, at the same time, assuring complete visibility on the overall infrastructure. Also, all logs and network packets are collected and saved in real time and analyze them in connection with the latest external threat information such as harmful IPs and malicious URLs, various threat elements can be quickly and effectively detected, blocked and prevented.
Many Enterprises and Institutions in the world are introducing the Cloud. Accordingly, security administrators must perform tasks in various services and systems, from single and multi-cloud to on-premises systems, depending on the purpose of the service.
SPiDER TM provides complete versatility in increasingly complex infrastructure environments. It supports the safe operation of IT infrastructure by acquiring comprehensive insights into single and multi-cloud environments as well as on-premises environments.
Visualization technology makes it easy to see at a glance by selecting only meaningful information from the ever-evolving security threats and exponentially accumulating security data and It enables more efficient security operation. SPiDER TM's Unified Dashboard visualizes vast amounts of security data, enabling security administrators to intuitively understand the security status of the entire network and make quick decisions.
Highlights
- Analyze internal information and external threats in connection with IGLOO CTI
- Provide process and function optimized for Managed Security Services
- Collect and analyze all types of logs and network packets
Details
Pricing
Instance type | Product cost/hour | EC2 cost/hour | Total/hour |
---|---|---|---|
m5.4xlarge Recommended | $0.00 | $0.944 | $0.944 |
m5.8xlarge | $0.00 | $1.888 | $1.888 |
m5.12xlarge | $0.00 | $2.832 | $2.832 |
Additional AWS infrastructure costs
Type | Cost |
---|---|
EBS General Purpose SSD (gp2) volumes | $0.114/per GB/month of provisioned storage |
Vendor refund policy
No refunds
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Change OS from centos to rocky 8.6
Additional details
Usage instructions
- Deploy AMI
- Configure Security group to allow access to 514/udp for syslog
- Configure Security group to allow access to 10011/tcp for Agent data
- Configure Security group to allow access to 443/tcp, 8983/tcp for for web page access
- Log into to new instance via SSH
- Run sudo /data/SIEM/extend.sh
- After 5-10 minutes of initialization and updates, the UI can be accessed via HTTPS. (https://<EC2_Instance_Public_IP>/siem)
Resources
Vendor resources
Support
Vendor support
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.