The HP ArcSight Security Intelligence platform is the industry's leading security information and event management (SIEM) solution for collecting, analyzing and assessing security events. ArcSight ESM sifts through millions of log records, and correlates them to find the critical events that matter, in real time. It transforms this data into actionable information, presenting it in dashboards, notifications, and reports so users can accurately prioritize security risks and compliance violations. In previous versions of the ArcSight software, as event-ingest volumes increased, write-heavy workloads slowed event correlation. Many organizations, including the US Internal Revenue Service (IRS), deploy a Fusion ioMemory-based system architecture to eliminate underlying I/O bottlenecks that can adversely impact ArcSight event correlation database processing and to dramatically improve performance.
Acting as a persistent memory tier operating at near-DRAM speeds in the server, Fusion ioMemory products are available in capacities from 365GB to 10TB and have been architected to ensure high reliability and endurance with linear performance scalability.
HP's highly-anticipated ArcSight ESM 6.0 release includes enhancements that make a joint ArcSight and Fusion ioMemory solution even more powerful. ESM 6.0 replaces the Oracle database that powered ArcSight ESM with HP's own CORR- engine. Joint ArcSight ESM 6.0 and Fusion ioMemory solutions can analyze much more data, much faster, on much less infrastructure, as compared to hard disk-based solutions, while also reducing capital and operating costs. Systems that implement this solution can achieve the following benefits:
This gives ArcSight customers more security capabilities and the ability to detect more incidents and analyze more data in the same footprint and in much less time.
Organizations can achieve maximum throughput on the smallest server footprint by moving the entire database onto Fusion ioMemory products deployed in the host server. Because all data is sourced from Fusion ioMemory rather than from slower rotating media such as disk drives, this configuration offers the highest possible events-per-second. Multiple Fusion ioMemory products can be aggregated together for a larger single volume of up to 40TB of capacity per server.
Example Solution Configuration
If your data set is too large to fit within a single server, you can achieve similar performance improvements by deploying a shared storage node built with SanDisk ION Accelerator™ software and Fusion ioMemory products configured in a single SanDisk ION Accelerator appliance. Any number of these SanDisk ION Accelerator shared storage nodes can be connected to a single ArcSight database server. The database can then be portioned to take advantage of this additional high-performance shared flash storage capacity.
ION Shared Storage Node Configuration
With the previous version of ArcSight, customers typically achieved approximately 35,000 events per second. With ArcSight 6.0, customers are able to double the performance of Fusion ioMemory-based systems and achieve an order of magnitude (10X) improvement over the performance of hard disk based systems.
The US Internal Revenue Service (IRS) recently tested ArcSight 6.0 on an HP DL580 G7 server configured with four Fusion ioMemory 2.4TB ioDrive®2 Duo cards. Using Bleep, ArcSight's built-in performance tool, the IRS achieved up to 70,000 events per second with a base install. After disabling default content, they averaged 109,000 events per second with peak performance at 135,000 events per second. When asked about impact on user experience, the IRS engineer said, “Running Fusion ioMemory solutions and the ArcSight CORR database, our query times have gone from over 30 minutes to under 30 seconds.”
1. For maximum performance, place the entire database, including logs onto Fusion ioMemory products, either within the server or using the ION Accelerator shared storage node option.
2. When working with large datasets that cannot fit within a single server, utilize one or more ION shared storage nodes.
HP ArcSight ESM 6.0 and Fusion ioMemory joint solutions enable organizations to create simple ArcSight systems that deliver consistent high-performance, low-latency responses—even as ingest load increases. Fusion ioMemory products integrate directly with the host server, providing cost-effective high-performance capacity operating at near-DRAM speeds for active data. Combining Fusion ioMemory solutions with ArcSight ESM 6.0 results in a faster, more resilient, and simpler system that dramatically improves ArcSight performance.
For More Information
Contact a SanDisk® representative, 1-800-578-6007 or firstname.lastname@example.org
The performance results discussed herein are based on testing and use of the described products. Results and performance may vary according to configurations and systems, including drive capacity, system architecture and applications.
Whether you'd like to ask a few initial questions or are ready to discuss a SanDisk solution tailored to your organizations's needs, the SanDisk sales team is standing by to help.
We're happy to answer your questions, so please fill out the form below so we can get started. If you need to talk to the sales team immediately, please phone: 800.578.6007
Thank you. We have received your request.