Too much data can be a good or bad thing.
Pros
- The options available for auditing are outstanding.
- The system has very good reliability and tuning options for the agents on the servers.
- The data gathered is fantastic and presented in a format that is easily readable for auditors.
- For on prem usage our servers have had no issues. The Linux is extremely resilient and we have no issues with the boxes.
Cons
- Navigation of the menus can get confusing pretty quickly. Since there are so many, it is extremely easy to get lost. Almost too many options and data.
- Configuring the agents can be very difficult if you are new to it. Having to save after every single change made to an agent during a configuration can be very tedious. Also having to make sure certain options are checked off in two separate places for a single option is very annoying.
- Navigation of the menus is not always intuitive and not very obvious that the option you are looking change is located in that menu.
Most Important Features
- The number of options available that we can audit for outside of the auto options
- The auto configurations that go along way for making sure PCI and HIPAA data selections are selected for audit data.
- The failover options and logging options are very robust and function really well. The system is rock steady.
Return on Investment
- A big negative that we have to be aware of system overhead where the agent is loaded. When going through the HiTrust certification the number of items that we wanted to to audit where severely taxing the database performance of the systems and causing issues with customer facing systems. We make sure that are only choosing what is necessary now.
- A even bigger positive is the ease of which our audits are completed for the databases. So long as we are collecting the correct data points it is a snap to export and provide exactly what is being asked for.
- The peace of mind it provides us knowing the data being collected is correct and easily retrieved. It gives us alot of peace of mind.
Other Software Used
Rapid7 InsightVM (Nexpose), Palo Alto Networks Cortex XSOAR (formerly Demisto), Palo Alto Networks GlobalProtect Mobile Security Manager

