﻿<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
  <channel>
    <title>LOGbinder</title>
    <description>All things relevant to LOGbinder</description>
    <link>http://www.logbinder.com/blog/default.aspx</link>
    <language>en-us</language>
    <copyright>Copyright (c) 2011 Monterey Technology Group, Inc., All rights reserved</copyright>
    <webMaster>info@logbinder.com</webMaster>
    <generator>Powered by Bloget</generator>
    <item>
      <title>LOGbinder 3.6 released!</title>
      <pubDate>Thu, 14 Mar 2013 21:35:49 GMT</pubDate>
      <link>http://www.logbinder.com/blog/default.aspx?p=c5c3d28e-4035-466b-bfcf-f2400a9da59d</link>
      <guid isPermaLink="false">c5c3d28e-4035-466b-bfcf-f2400a9da59d</guid>
      <author>info@logbinder.com</author>
      <description>&lt;DIV&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;An exciting &lt;A href="http://www.logbinder.com/products/LOGbinderSP/Default.aspx"&gt;new version of LOGbinder SP has been released&lt;/A&gt;. Here is what’s new in LOGbinder SP 3.6:&lt;/P&gt;
&lt;P&gt;First of all, there are now more output options. Besides the LOGbinder SP event log and the Security log, LOGbinder SP (and all other LOGbinder products, such as LOGbinder EX and LOGbinder SQL) can now send outputs to your Syslog server and also has the ability to output in to a Syslog text file. These Syslog outputs can also be formatted in ArcSight CEF (Common Event Format). Yes, LOGbinder SP is now ArcSight CEF certified.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;Added output options:&lt;/STRONG&gt; &lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN-LEFT: 1in"&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;Syslog-Generic &lt;/STRONG&gt;and&lt;STRONG&gt; Syslog-Generic (File)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN-LEFT: 1in"&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;Syslog-CEF &lt;/STRONG&gt;and&lt;STRONG&gt; Syslog-CEF (File)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Additional improvements:&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;Added new features:&lt;/STRONG&gt; &lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN-LEFT: 1in"&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;Option for adjusting properties of multiple inputs&lt;/STRONG&gt; – If multiple inputs are selected, and then Properties is opened, the audit policy can be adjusted for all of the selected site collections at the same time.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN-LEFT: 1in"&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;Option to exclude personal sites from default audit policy&lt;/STRONG&gt; – With this option set, the default audit policy can exclude personal site collections, such as those with “/sites”, “/my”, and “/my/personal” prefixes.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN-LEFT: 1in"&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;Central Administration site collection monitoring&lt;/STRONG&gt; – Site collection(s) contained in Central Administration can now be monitored by LOGbinder SP.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN-LEFT: 1in"&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;Option to “&lt;EM&gt;Conserve resources with lookups”&lt;/EM&gt;&lt;/STRONG&gt;– If enabled, certain high-cost lookups are skipped—which speeds up processing and reduces memory consumption. (Please note that since some details in certain events will be omitted with this option, this should be chosen only in cases when performance problems become completely unacceptable.)&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;Added new events:&lt;/STRONG&gt; &lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN-LEFT: 1in"&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;Event #63 “Content type imported”&lt;/STRONG&gt; – This event was added based on our customers’ requests.&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN-LEFT: 1in"&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;Event #550 “LOGbinder process report”&lt;/STRONG&gt; – Each time all the site collections have been processed, LOGbinder SP will write this event to the Application event log. It lists the number of site collections processed, the start and end time, and the time elapsed.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN-LEFT: 1in"&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'"&gt;o&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;Event #558 “LOGbinder process warning”&lt;/STRONG&gt; – This warning message will be written to the Application log if any site collections have been behind in its processing for more than 24 consecutive hours.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in"&gt;&lt;SPAN style="FONT-FAMILY: Symbol"&gt;·&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;Fixed several small issues&lt;/STRONG&gt; &lt;/P&gt;
&lt;P&gt;If you are a LOGbinder SP 3.x user already, upgrading is easy: &lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN-LEFT: 0.75in"&gt;&lt;SPAN&gt;1.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Stop the LOGbinder service&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN-LEFT: 0.75in"&gt;&lt;SPAN&gt;2.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Close the LOGbinder control panel&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN-LEFT: 0.75in"&gt;&lt;SPAN&gt;3.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Install LOGbinder 3.6 on top of your current version. &lt;/P&gt;
&lt;P&gt;If you are not a LOGbinder SP user yet, why not give it a try for 30 days? &lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;Please&amp;nbsp;&lt;A href="http://www.logbinder.com/form.aspx?action=download"&gt;&lt;FONT color=#0000ff&gt;download LOGbinder&lt;/FONT&gt;&lt;/A&gt; today or &lt;A href="http://www.logbinder.com/form.aspx?action=spAsk"&gt;&lt;FONT color=#0000ff&gt;contact us for a demo&lt;/FONT&gt;&lt;/A&gt;.&lt;/P&gt;&lt;/DIV&gt;</description>
      <category>LOGbinder SP</category>
    </item>
    <item>
      <title>ArcSight Connector for Exchange PowerShell and LOGbinder EX</title>
      <pubDate>Tue, 05 Mar 2013 22:34:04 GMT</pubDate>
      <link>http://www.logbinder.com/blog/default.aspx?p=39770285-e0bd-4ccf-8527-b9bc9b8c0627</link>
      <guid isPermaLink="false">39770285-e0bd-4ccf-8527-b9bc9b8c0627</guid>
      <author>info@logbinder.com</author>
      <description>&lt;div&gt;ArcSight is an excellent tool, and together with ArcSight Connector, you can collect and process data from a variety of sources. But in some cases, you can do better.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;The following paper looks at how you can significantly improve your experience with ArcSight when processing logs from Exchange Servers. In this brief comparison, we examine how you will benefit by replacing ArcSight Connector for Exchange Powershell with LOGbinder EX, our CEF certified product. It also highlights the potential impacts you will avoid by doing so.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Download Comparison: &lt;a href="http://www.logbinder.com/form.aspx?action=CompArcConnVsLBEX"&gt;ArcSight Connector for Exchange PowerShell and LOGbinder EX&lt;/a&gt;.&lt;/div&gt;</description>
      <category>LOGbinder EX</category>
    </item>
    <item>
      <title>ArcSight Connector for SQL Server Audit and LOGbinder SQL</title>
      <pubDate>Tue, 05 Mar 2013 22:31:46 GMT</pubDate>
      <link>http://www.logbinder.com/blog/default.aspx?p=f1e8980b-9ef3-4984-bdb0-c6a9c01eb18d</link>
      <guid isPermaLink="false">f1e8980b-9ef3-4984-bdb0-c6a9c01eb18d</guid>
      <author>info@logbinder.com</author>
      <description>&lt;div&gt;ArcSight is an excellent tool, and together with ArcSight Connector, you can collect and process data from a variety of sources.&amp;nbsp;&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;The following paper looks at how you can significantly improve your experience with ArcSight when processing logs from SQL Server Audit. In this brief comparison, we examine how you will benefit by replacing ArcSight Connector for SQL Servel Audit with LOGbinder SQL, our CEF certified product. It also highlights the potential impacts you will avoid by doing so.&lt;/div&gt;&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;Download Comparison: &lt;a href="http://www.logbinder.com/form.aspx?action=CompArcConnVsLBSQL"&gt;ArcSight Connector for SQL Server Audit and LOGbinder SQL&lt;/a&gt;.&lt;/div&gt;</description>
      <category>LOGbinder SQL</category>
    </item>
    <item>
      <title>New Whitepaper:  Top 6 Security Events to Audit in SharePoint</title>
      <pubDate>Tue, 05 Mar 2013 22:00:49 GMT</pubDate>
      <link>http://www.logbinder.com/blog/default.aspx?p=d0392c11-a740-4237-b4c2-7194ad4ce3e1</link>
      <guid isPermaLink="false">d0392c11-a740-4237-b4c2-7194ad4ce3e1</guid>
      <author>info@logbinder.com</author>
      <description>&lt;P&gt;Click &lt;A href="http://www.logbinder.com/form.aspx?action=Top6SP"&gt;here&lt;/A&gt; to get a copy of Randy Franklin Smith's new whitepaper:&amp;nbsp;&lt;A href="http://www.logbinder.com/form.aspx?action=Top6SP"&gt;Top 6 Security Events to Audit in SharePoint&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;You can find other SharePoint whitepapers at on our Resources page at &lt;A href="http://www.logbinder.com/products/logbindersp/resources/default.aspx"&gt;LOGbinder.com&lt;/A&gt;.&lt;/P&gt;</description>
      <category>LOGbinder SP</category>
    </item>
    <item>
      <title>LOGbinder EX for Exchange Released: Bridge the Gap between Exchange and Your SIEM</title>
      <pubDate>Mon, 18 Feb 2013 19:54:19 GMT</pubDate>
      <link>http://www.logbinder.com/blog/default.aspx?p=83ba2e95-571e-4460-ad54-270e7ca43be6</link>
      <guid isPermaLink="false">83ba2e95-571e-4460-ad54-270e7ca43be6</guid>
      <author>info@logbinder.com</author>
      <description>

&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;font face="Calibri"&gt;I’m excited to announce the release of &lt;/font&gt;&lt;a href="http://www.logbinder.com/products/LOGbinderEX"&gt;&lt;font color="#0000ff" face="Calibri"&gt;LOGbinder EX for Exchange
Server&lt;/font&gt;&lt;/a&gt;&lt;font face="Calibri"&gt; which bridges the gap between Exchange and your SIEM.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;font face="Calibri"&gt;With today’s ever-growing compliance burden and
threat-scape, obtaining visibility into the dominant messaging platform is
crucial to security and business risk management for most organizations. &lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;font face="Calibri"&gt;Thankfully, Exchange Server provides an audit trail of non-owner
access to mailboxes as well as privileged activity by Exchange administrators. &lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;font face="Calibri"&gt;With mailbox auditing, you can detect&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p style="margin: 0in 0in 0pt 0.5in; text-indent: -0.25in; mso-list: l0 level1 lfo1;" class="MsoListParagraphCxSpFirst"&gt;&lt;span style="font-family: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;·&lt;span style='font: 7pt/normal "Times New Roman"; font-size-adjust: none; font-stretch: normal;'&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face="Calibri"&gt;Users viewing an executive’s confidential email&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p style="margin: 0in 0in 0pt 0.5in; text-indent: -0.25in; mso-list: l0 level1 lfo1;" class="MsoListParagraphCxSpMiddle"&gt;&lt;span style="font-family: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;·&lt;span style='font: 7pt/normal "Times New Roman"; font-size-adjust: none; font-stretch: normal;'&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face="Calibri"&gt;Impersonated, fraudulent emails&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p style="margin: 0in 0in 0pt 0.5in; text-indent: -0.25in; mso-list: l0 level1 lfo1;" class="MsoListParagraphCxSpMiddle"&gt;&lt;span style="font-family: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;·&lt;span style='font: 7pt/normal "Times New Roman"; font-size-adjust: none; font-stretch: normal;'&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face="Calibri"&gt;Administrators exporting copies of entire
mailboxes&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p style="margin: 0in 0in 10pt 0.5in; text-indent: -0.25in; mso-list: l0 level1 lfo1;" class="MsoListParagraphCxSpLast"&gt;&lt;span style="font-family: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;·&lt;span style='font: 7pt/normal "Times New Roman"; font-size-adjust: none; font-stretch: normal;'&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face="Calibri"&gt;Deletion of emails to cover up evidence&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;font face="Calibri"&gt;With administrator auditing, you can detect&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p style="margin: 0in 0in 0pt 0.5in; text-indent: -0.25in; mso-list: l1 level1 lfo2;" class="MsoListParagraphCxSpFirst"&gt;&lt;span style="font-family: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;·&lt;span style='font: 7pt/normal "Times New Roman"; font-size-adjust: none; font-stretch: normal;'&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face="Calibri"&gt;Exports of mailboxes&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p style="margin: 0in 0in 0pt 0.5in; text-indent: -0.25in; mso-list: l1 level1 lfo2;" class="MsoListParagraphCxSpMiddle"&gt;&lt;span style="font-family: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;·&lt;span style='font: 7pt/normal "Times New Roman"; font-size-adjust: none; font-stretch: normal;'&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face="Calibri"&gt;Copies of entire mailbox databases&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p style="margin: 0in 0in 0pt 0.5in; text-indent: -0.25in; mso-list: l1 level1 lfo2;" class="MsoListParagraphCxSpMiddle"&gt;&lt;span style="font-family: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;·&lt;span style='font: 7pt/normal "Times New Roman"; font-size-adjust: none; font-stretch: normal;'&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face="Calibri"&gt;Security configuration changes to Exchange&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p style="margin: 0in 0in 0pt 0.5in; text-indent: -0.25in; mso-list: l1 level1 lfo2;" class="MsoListParagraphCxSpMiddle"&gt;&lt;span style="font-family: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;·&lt;span style='font: 7pt/normal "Times New Roman"; font-size-adjust: none; font-stretch: normal;'&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face="Calibri"&gt;Access control changes to groups, roles, and
permissions&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p style="margin: 0in 0in 10pt 0.5in; text-indent: -0.25in; mso-list: l1 level1 lfo2;" class="MsoListParagraphCxSpLast"&gt;&lt;span style="font-family: Symbol; mso-bidi-font-family: Symbol; mso-fareast-font-family: Symbol;"&gt;&lt;span style="mso-list: Ignore;"&gt;·&lt;span style='font: 7pt/normal "Times New Roman"; font-size-adjust: none; font-stretch: normal;'&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face="Calibri"&gt;Modifications to Exchange policies involving
retention, mobile device policy, information rights management, federation, and
more&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;font face="Calibri"&gt;But, like many application audit logs today, the information
is trapped within the application and specific to Exchange, audit logs are
actually maintained in mailboxes. Applications benefit from internal audit
capability but ultimately audit logs should be copied as frequently as possible
to a separate, isolated log management system.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;font face="Calibri"&gt;LOGbinder EX efficiently process native Exchange audit data
and translates cryptic codes, yielding an easy-to-understand Exchange audit log
to the Windows event log or syslog where any log management/SIEM solution can
take over with collection, alerting, reporting, and secure archival. LOGbinder
EX performs these functions on both the administrator audit log and the mailbox
audit log.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;font face="Calibri"&gt;LOGbinder EX can be installed on most any server in your
domain; there's no need to install it on any of your Exchange servers thus
preventing impact on production mail flow.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;font face="Calibri"&gt;Exchange audit logs need to be monitored and they belong in
your SIEM.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;Use LOGbinder EX to bridge
the gap.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;

&lt;span style='line-height: 115%; font-family: "Calibri","sans-serif"; font-size: 11pt; mso-bidi-font-family: "Times New Roman"; mso-bidi-theme-font: minor-bidi; mso-fareast-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;'&gt;Please &lt;a href="http://www.logbinder.com/form.aspx?action=LOGbinderEXDL"&gt;&lt;font color="#0000ff"&gt;download LOGbinder&lt;/font&gt;&lt;/a&gt;
today or &lt;a href="http://www.logbinder.com/form.aspx?action=exAsk"&gt;&lt;font color="#0000ff"&gt;contact us
for a demo&lt;/font&gt;&lt;/a&gt;.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;I’ve also got a
whitepaper that explains Exchange Server’s 3 Audit Logs and how LOGbinder and
your SIEM fit in.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;&lt;a href="http://www.logbinder.com/form.aspx?action=LBexWPComp"&gt;&lt;font color="#0000ff"&gt;Click here to read
the whitepaper&lt;/font&gt;&lt;/a&gt;.&lt;/span&gt;</description>
      <category>LOGbinder EX</category>
    </item>
    <item>
      <title>Work around if LOGbinder SP is having SQL database issues</title>
      <pubDate>Fri, 14 Dec 2012 23:45:22 GMT</pubDate>
      <link>http://www.logbinder.com/blog/default.aspx?p=61b9a9e0-cbd8-496f-8b04-0bd86549b7bf</link>
      <guid isPermaLink="false">61b9a9e0-cbd8-496f-8b04-0bd86549b7bf</guid>
      <author>info@logbinder.com</author>
      <description>

&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;font face="Calibri"&gt;A problem that might occur when using LOGbinder SP stems
from the fact that SharePoint does not behave the same way through its web
interface and through its API. &lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;font face="Calibri"&gt;As a result, even though the account has been added
correctly via Central Administration or the SharePoint site collection settings
page, and has no problem when using the account in the SharePoint web
interfaces, the privileges granted are not sufficient when third-party software
uses the public SharePoint APIs, resulting in an ‘access denied’ error.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;font face="Calibri"&gt;In this blog, we will provide a workaround for the problem.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;font face="Calibri"&gt;SYMPTOMS:&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p style="margin: 0in 0in 10pt 0.5in;" class="MsoNormal"&gt;&lt;font face="Calibri"&gt;Even though the LOGbinder user is definitely
a farm administrator, you get an event from LOGbinder like this:&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p style="margin: 0in 0in 10pt 1in;" class="MsoNormal"&gt;&lt;font face="Calibri"&gt;Unable to configure SharePoint
export. Details: Cannot open database "WSS_Content" requested by the
login. The login failed. Login failed for user
'SHAREPOINTSERVER\logbinderaccount'. SQL Database 'WSS_Content' on SQL Server
instance 'SHAREPOINTSERVER\OfficeServers' not found. Additional error
information from SQL Server is included below. Cannot open database
"WSS_Content" requested by the login. The login failed. Login failed
for user 'SHAREPOINTSERVER\logbinderaccount'.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;font face="Calibri"&gt;CAUSE:&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p style="margin: 0in 0in 10pt 0.5in;" class="MsoNormal"&gt;&lt;font face="Calibri"&gt;SharePoint behaves differently when
accessing it via its web interface versus accessing it via standard Microsoft
SharePoint API’s in third-party software. As a result, it might happen that you
are able to perform certain operations through the SharePoint web interface,
but when doing the same from a third-party application (such as LOGbinder SP)
that is using only standard, published SharePoint API’s, the same operations
performed by the same user do not work.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;font face="Calibri"&gt;If this occurs, you will likely want to perform the
following workaround, so please follow these steps:&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p style="margin: 0in 0in 10pt 0.5in; text-indent: -0.25in; mso-list: l0 level1 lfo1;" class="MsoListParagraph"&gt;&lt;span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;font face="Calibri"&gt;1.&lt;/font&gt;&lt;span style='font: 7pt/normal "Times New Roman"; font-size-adjust: none; font-stretch: normal;'&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face="Calibri"&gt;Go to &lt;i style="mso-bidi-font-style: normal;"&gt;Central
Administration&lt;/i&gt; and under “System Settings” click on “Manage servers in this
farm”.&lt;/font&gt;&lt;/p&gt;

&lt;img alt="CentralAdmin" src=" http://www.logbinder.com/images/CentralAdmin.png " width="781" height="396"&gt;&lt;p style="margin: 0in 0in 10pt 0.5in; text-indent: -0.25in; mso-list: l0 level1 lfo1;" class="MsoListParagraph"&gt;&lt;span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;font face="Calibri"&gt;2.&lt;/font&gt;&lt;span style='font: 7pt/normal "Times New Roman"; font-size-adjust: none; font-stretch: normal;'&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face="Calibri"&gt;Make a note of the “Farm Information” at the top
of the page, for example:&lt;/font&gt;&lt;/p&gt;
&lt;img alt="FarmInfo" src="http://www.logbinder.com/images/FarmInfo.png " width="286" height="114"&gt;&lt;p style="margin: 0in 0in 10pt 0.5in; text-indent: -0.25in; mso-list: l0 level1 lfo1;" class="MsoListParagraph"&gt;&lt;span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;font face="Calibri"&gt;3.&lt;/font&gt;&lt;span style='font: 7pt/normal "Times New Roman"; font-size-adjust: none; font-stretch: normal;'&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face="Calibri"&gt;Using the server/instance specified above in the
Farm Information, open &lt;i style="mso-bidi-font-style: normal;"&gt;SQL Server
Management Studio&lt;/i&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p style="margin: 0in 0in 10pt 0.5in; text-indent: -0.25in; mso-list: l0 level1 lfo1;" class="MsoListParagraph"&gt;&lt;span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"&gt;&lt;span style="mso-list: Ignore;"&gt;&lt;font face="Calibri"&gt;4.&lt;/font&gt;&lt;span style='font: 7pt/normal "Times New Roman"; font-size-adjust: none; font-stretch: normal;'&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face="Calibri"&gt;Under the &lt;b style="mso-bidi-font-weight: normal;"&gt;SharePoint_Config&lt;/b&gt;
database (exact database may vary by installation), go to Security, then Users.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;Make sure that both the service account that
LOGbinder SP is using, as well as the account to run LOGbinder SP Configuration
(if not the same) have &lt;b style="mso-bidi-font-weight: normal;"&gt;db_owner&lt;/b&gt; role
set.&lt;/font&gt;&lt;/p&gt;&lt;img alt="SPConfig" src="http://www.logbinder.com/images/SPConfig.png " width="224" height="259"&gt;&lt;img alt="DBRoleMem" src="http://www.logbinder.com/images/DBRoleMem.png " width="240" height="153"&gt;&lt;p style="margin: 0in 0in 10pt 0.5in; text-indent: -0.25in; mso-list: l0 level1 lfo1;" class="MsoListParagraph"&gt;&lt;font face="Calibri"&gt;5&lt;span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"&gt;&lt;span style="mso-list: Ignore;"&gt;.&lt;span style='font: 7pt/normal "Times New Roman"; font-size-adjust: none; font-stretch: normal;'&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Repeat the previous step for the &lt;b style="mso-bidi-font-weight: normal;"&gt;SharePoint_AdminContent&lt;/b&gt; database (exact
database may vary by installation).&lt;/font&gt;&lt;/p&gt;&lt;p style="margin: 0in 0in 10pt 0.5in; text-indent: -0.25in; mso-list: l0 level1 lfo1;" class="MsoListParagraph"&gt;&lt;font face="Calibri"&gt;&lt;span style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin;"&gt;&lt;span style="mso-list: Ignore;"&gt;6.&lt;span style='font: 7pt/normal "Times New Roman"; font-size-adjust: none; font-stretch: normal;'&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Note: If there are any other config databases
for SharePoint and the problem still occurs, make sure you do this steps for those
databases as well.&lt;/font&gt;&lt;/p&gt;&lt;font face="Calibri"&gt;&lt;p style="margin: 0in 0in 10pt 0.5in;" class="MsoListParagraphCxSpLast"&gt;(Also see the additional note below.)&lt;/p&gt;&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;This should implement the workaround.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;&lt;/p&gt;&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;Additional note:&lt;/p&gt;&lt;p style="margin: 0in 0in 10pt 0.5in;" class="MsoNormal"&gt;A similar issue may occur with
administrator privileges to SharePoint site collections: even though the
service account is listed as a site collection administrator in SharePoint’s
user interface, you receive an error that the user is not a site collection
administrator.&lt;/p&gt;&lt;p style="margin: 0in 0in 10pt 0.5in;" class="MsoListParagraph"&gt;If this occurs, perform similar steps as described
above, but to the WSS_Content database. In this case, you would need to add
only the LOGbinder SP service account, since the account you use to run the
LOGbinder GUI does not need site collection administrator privilege.&lt;/p&gt;&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;It has to be emphasized that we don’t consider the above
steps to be a fix, just a workaround to this SharePoint problem, which affects
not only LOGbinder, but many other applications too. See, for example &lt;a href="http://blog.krichie.com/2008/09/11/unrestricted-access-via-sharepoint-object-model-from-console-applications/"&gt;&lt;font color="#0000ff"&gt;this&lt;/font&gt;&lt;/a&gt;,
&lt;a href="http://blog.sqlauthority.com/2009/08/20/sql-server-fix-error-cannot-open-database-requested-by-the-login-the-login-failed-login-failed-for-user-nt-authoritynetwork-service/"&gt;&lt;font color="#0000ff"&gt;this&lt;/font&gt;&lt;/a&gt;,
or &lt;a href="http://sharepoint.stackexchange.com/questions/18515/add-login-account-to-access-wss-content"&gt;&lt;font color="#0000ff"&gt;this&lt;/font&gt;&lt;/a&gt;
article. Even Microsoft says that it can happen &lt;font color="#ff0000"&gt;&lt;u&gt;and&lt;/u&gt;&lt;/font&gt; that &lt;font color="#ff0000"&gt;&lt;u&gt;sometimes&lt;/u&gt;&lt;/font&gt; “&lt;a href="http://support.microsoft.com/kb/981490"&gt;&lt;font color="#0000ff"&gt;you cannot open a database in the
SharePoint Management console of SharePoint Foundation 2010 or SharePoint
Server 2010 even though you are a farm administrator who has full administrator
rights&lt;/font&gt;&lt;/a&gt;”, unless you are a member of the db_owner fixed database role for
the database.&lt;/p&gt;&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;As a security company we strongly advocate the principles of
least privilege, which we also apply in the design of our LOGbinder
products.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/span&gt;There is no reason why the
LOGbinder service account should be granted any rights in SQL server, much less
database owner. However, until Microsoft fixes this, the only way to get a
third-party application work through SharePoint API is to implement the
workaround outlined above.&lt;/p&gt;&lt;/font&gt;&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;font face="Times New Roman"&gt;

&lt;/font&gt;&lt;/p&gt;</description>
      <category>LOGbinder SP</category>
    </item>
    <item>
      <title>How does LOGbinder SP detect log tampering?</title>
      <pubDate>Fri, 14 Dec 2012 21:35:06 GMT</pubDate>
      <link>http://www.logbinder.com/blog/default.aspx?p=5feb2004-a809-45bd-8edc-3c213a5776fb</link>
      <guid isPermaLink="false">5feb2004-a809-45bd-8edc-3c213a5776fb</guid>
      <author>info@logbinder.com</author>
      <description>

&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;span lang="EN-BZ"&gt;&lt;font face="Calibri"&gt;While LOGbinder SP is processing events, it
will perform actions that generate SharePoint events. What happens, though, if
these same actions are performed maliciously by a SharePoint user? Will this compromise
the integrity of the audit trail? No. LOGbinder SP can detect log tampering.
How?&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p style="margin: 0in 0in 10pt;" class="MsoNormal"&gt;&lt;span lang="EN-BZ"&gt;&lt;font face="Calibri"&gt;In order to distinguish between authorized
and unauthorized changes, LOGbinder SP (version 3 and later), when processing
these events, will indicate whether it performed the action itself, or the
action might be unauthorized. A tamper warning will be generated in the
following cases:&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p style="margin: 0in 0in 0pt 0.5in; text-indent: -0.25in; mso-list: l0 level1 lfo1;" class="MsoListParagraphCxSpFirst"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;" lang="EN-BZ"&gt;&lt;span style="mso-list: Ignore;"&gt;·&lt;span style='font: 7pt/normal "Times New Roman"; font-size-adjust: none; font-stretch: normal;'&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;font face="Calibri"&gt;&lt;i style="mso-bidi-font-style: normal;"&gt;&lt;span lang="EN-BZ"&gt;Audit policy change:&lt;/span&gt;&lt;/i&gt;&lt;span lang="EN-BZ"&gt; When processing
event #11 “Site collection audit policy changed” or #12 “Audit policy changed,”
LOGbinder will determine if the change overrides the settings in LOGbinder. If
so, LOGbinder will reset the audit policy and generate a tamper warning (#60
“Possible tampering warning”).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p style="margin: 0in 0in 10pt 0.5in; text-indent: -0.25in; mso-list: l0 level1 lfo1;" class="MsoListParagraphCxSpLast"&gt;&lt;span style="font-family: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;" lang="EN-BZ"&gt;&lt;span style="mso-list: Ignore;"&gt;·&lt;span style='font: 7pt/normal "Times New Roman"; font-size-adjust: none; font-stretch: normal;'&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;i style="mso-bidi-font-style: normal;"&gt;&lt;span lang="EN-BZ"&gt;&lt;font face="Calibri"&gt;Audit logs deleted:&lt;/font&gt;&lt;/span&gt;&lt;/i&gt;&lt;span lang="EN-BZ"&gt;&lt;font face="Calibri"&gt; When processing
event #20 “SharePoint audit logs deleted,” LOGbinder will determine whether
LOGbinder deleted the logs, and indicate it in an additional line added to this
event. The line “Purge performed by LOGbinder” will show value “Yes” if LOGbinder
performed the purge, and “No” otherwise.&lt;span style="mso-spacerun: yes;"&gt;&amp;nbsp;
&lt;/span&gt;In the latter case, a tamper warning event (#60 “Possible tampering
warning”) will be generated. &lt;br&gt;
Note: If it cannot determined whether the logs were deleted by LOGbinder SP,
the “Purge performed by LOGbinder” value will be set to “Indeterminate”. This
typically occurs when processing backlog events, i.e. those produced before
LOGbinder started processing the site collection.&lt;o:p&gt;&lt;/o:p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;

&lt;span style='line-height: 115%; font-family: "Calibri","sans-serif"; font-size: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: "Times New Roman"; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-BZ; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;' lang="EN-BZ"&gt;By alerting on event #60 “Possible tampering
warning”, malicious audit tampering attempts can be detected, so the audit
trail is not compromised.&lt;/span&gt;</description>
      <category>LOGbinder SP</category>
    </item>
    <item>
      <title>New Whitepaper by Randy Franklin Smith &amp;quot;Comparing SharePoint's 4 Audit Logs for Security and SIEM Integration&amp;quot; </title>
      <pubDate>Sat, 24 Nov 2012 23:21:02 GMT</pubDate>
      <link>http://www.logbinder.com/blog/default.aspx?p=c148c805-a318-4d26-a549-135f1d784e67</link>
      <guid isPermaLink="false">c148c805-a318-4d26-a549-135f1d784e67</guid>
      <author>info@logbinder.com</author>
      <description>&lt;p&gt;This whitepaper by Randy Franklin Smith, provides an overview of the 4 different 
logs in SharePoint and discusses their relative merits in terms of security 
value and how to integrate with your SIEM.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.logbinder.com/form.aspx?action=LB4LogsWP"&gt;Click here to download it now.&lt;/a&gt;&lt;/p&gt;</description>
      <category>LOGbinder SP</category>
    </item>
    <item>
      <title>You want to run audit reports in SharePoint but LOGbinder SP purges the audit log</title>
      <pubDate>Tue, 20 Nov 2012 18:44:19 GMT</pubDate>
      <link>http://www.logbinder.com/blog/default.aspx?p=d9b3e709-6f1a-4731-a0c8-df5e3f97a187</link>
      <guid isPermaLink="false">d9b3e709-6f1a-4731-a0c8-df5e3f97a187</guid>
      <author>info@logbinder.com</author>
      <description>&lt;table border="0" width="500"&gt;
  &lt;tbody&gt;&lt;tr&gt;
    &lt;td&gt;LOGbinder  SP can automatically purge audit entries from SharePoint after they have been  processed by LOGbinder SP and forwarded to an event log or your SIEM/Log  Management solution.  This purging occurs  on a daily basis, but a buffer is maintained, so only entries older than 24  hours are purged. &lt;br&gt;
      This is  usually sufficient to satisfy security and compliance requirements through the audit  logs stored in the organization’s SIEM or log management solution. However, in  some rare instances, it might be necessary to leave the audit logs in  SharePoint in order to be able to run audit reports from within the SharePoint  environment.  The problem is that these  logs are no longer available in SharePoint, since LOGbinder SP purged them.&lt;br&gt;
    In this  case, the LOGbinder SP automatic purging feature needs to be disabled through  the Options dialog on the LOGbinder interface. Since it will not process events  it has already processed, not purging the logs from SharePoint will not create  duplicate events in your log management.&lt;/td&gt;
  &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td align="center"&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;img style="width: 236px; height: 372px;" alt="" align="middle" src="http://www.logbinder.com/images/LBblog02.jpg" width="152" height="246"&gt;&lt;/p&gt;&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
    &lt;td&gt;&lt;div align="center"&gt;
      &lt;p&gt;&lt;font color="#006699" size="2"&gt;Figure 1: Disable purging under LOGbinder SP Options&lt;/font&gt;&lt;font color="#006699" size="2"&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;
    &lt;/div&gt;&lt;/td&gt;
    &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;To avoid  the logs to accumulate in SharePoint, taking up valuable resources and potentially  degrading the performance of the site collection, SharePoint can be set to trim  the audit log. Under &lt;em&gt;Site Settings / Site  Collection Administration group / Site collection audit settings&lt;/em&gt; options  are available to trim audit logs when they reach a certain age (specified in  number of days) and optionally be stored in a document library.&lt;br&gt;
    &lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;&lt;img alt="" src="http://www.logbinder.com/images/LBblog01.jpg" width="578" height="172"&gt;&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td align="center"&gt;&lt;p&gt;&lt;font color="#006699" size="2"&gt;Figure 2: Enable trimming in SharePoint audit settings&lt;/font&gt; &lt;/p&gt;&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;Applying  these changes you can benefit from the managing your logs with your preferred  SIEM/Log management solution through LOGbinder, while still taking advantage of  having access to the audit logs from SharePoint.&lt;p&gt;&lt;br&gt;&amp;nbsp;&lt;/p&gt;&lt;/td&gt;
  &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;</description>
      <category>LOGbinder SP</category>
    </item>
    <item>
      <title>Whitepaper:  Comparing Exchange Server's™ 3 Audit Logs for Security and SIEM Integration</title>
      <pubDate>Fri, 16 Nov 2012 21:18:46 GMT</pubDate>
      <link>http://www.logbinder.com/blog/default.aspx?p=00106a55-d508-4909-8ab9-b6ab9ce70d72</link>
      <guid isPermaLink="false">00106a55-d508-4909-8ab9-b6ab9ce70d72</guid>
      <author>info@logbinder.com</author>
      <description>&lt;p&gt;This whitepaper by Randy Franklin Smith, provides an overview of the 3 different 
audit logs in Exchange and discusses their relative merits in terms of security 
value and how to integrate with your SIEM.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.logbinder.com/form.aspx?action=LBexWPComp"&gt;Download it now here.&lt;/a&gt;&lt;/p&gt;</description>
      <category>LOGbinder EX</category>
    </item>
  </channel>
</rss>