cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Does ELM is necessary?

Hello everybody, i am studying the SIEM solution, i see that the ELM is present on every Architecture but it is not clear for me if it is absolutely necessary. For example, if i do not have an explicit requirement for store raw logs, can i deploy an ESM and Receiver solution without ELM?.

English is not my native language so, i apologize in advance for any grammar error.

Thanks!

5 Replies
Former Member
Not applicable
Report Inappropriate Content
Message 2 of 6

Re: Does ELM is necessary?

I believe the minimum configuration you need is an ESM and to collect logs, a Collector.  The ELM is used for long term storage and is optional.  Some of the benefits include long term storage, the ability to do regex or more free form searches (if you don't know the exact field to look for) and access to a copy of the original data.

Re: Does ELM is necessary?

Thank you

Former Member
Not applicable
Report Inappropriate Content
Message 4 of 6

Re: Does ELM is necessary?

Yes, you can just use ESM and REC for the deployment if ELM is not a requirement. Usually ELM is used for long term storage and mainly from a compliance perspective. If the customer has a compliance requirement like PCI-DSS, ISO 27K then ELM is a must or else it depends on the requirements.

Regards,

Vinaya

Re: Does ELM is necessary?

Thank you very much Vinaya

Former Member
Not applicable
Report Inappropriate Content
Message 6 of 6

Re: Does ELM is necessary?

, in addition to above mentioned reasons for ELM, it also enables you to see raw packets in ESM. The raw packet is temporarily stored in ERC. However, if you have ELM, you can always see the raw packet. This is very useful during investigation analysis.

ELm_Archive.jpg

Regards,

Syed

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community