LogRhythm Enhances Security Analytics with Expanded Security Operations Capabilities
January 2023 by Marc Jacob
LogRhythm announced a series of expanded capabilities and integrations for its security operations solutions. The updates propel LogRhythm’s ability to be a much-needed force multiplier for overwhelmed security teams who are expected to confidently, effectively, and efficiently defend against cyberattacks.
Following the October launch of LogRhythm Axon, a groundbreaking, cloud-native security operations platform, the company is introducing new visualizations and powerful analytics that offer seamless visibility into potential security risks. Designed to streamline the experience of security analysts, Axon and its latest updates make it easier for teams to detect, investigate, and report on potential threats, reducing the burden of managing threats and the operating infrastructure.
This quarter’s enhancements span LogRhythm’s product portfolio to collectively enable SOC teams to detect and resolve threats more easily, improving analyst productivity and effectiveness. Additional enhancements and integrations with LogRhythm’s Axon, SIEM, NDR, and UEBA solutions released in this quarterly rollout include:
LogRhythm Axon
• New custom and out-of-the box analytics rules, including rules for MITRE ATT&CK detections
• New markdown widget and histogram widget cuts down on time spent searching for data
• Easily investigate log observations raised by analytics through the Observation Workflow
LogRhythm SIEM
• Improved administrative workflow for collection shortens time to configure, deploy, and manage log sources that require Open Collector
• Enhanced audit logging makes it easier to monitor suspicious activity and track when users make important changes
• Updated and expanded LogRhythm’s library of supported log sources
LogRhythm UEBA
• New detection models for Windows systems to quickly uncover hard to detect threats
LogRhythm NDR
• Improved blind spot detection and endpoint visibility through integration with Microsoft EDR
• Easily ingest data from VirusTotal with new configuration page
• Improved analyst experience with expanded UI improvements