The system must meet the following requirements:
The SIEM must support processing 6,000 events per second (EPS – events per second).
The SIEM must support scalability of EPS capacity.
The SIEM must support on-premise deployment within the Customer’s infrastructure.
The SIEM must support parsing of raw events from major operating systems such as Windows, Linux, FortiOS, and Oracle.
The SIEM must support the creation of custom parsers for non-standard event sources.
The SIEM must support modifying parsers via a graphical user interface (GUI) and deploying them to a running system.
The SIEM must include a set of correlation rules for various operating systems such as Windows, Linux, FortiOS, and Oracle.
The SIEM must support incident management capabilities.
The SIEM must support hierarchical log storage (Hot-Warm-Cold) to optimize search performance.
The SIEM must support data storage on external storage systems (e.g., NFS server).
The SIEM must support role-based access control (RBAC) to restrict access to the GUI and data at different levels.
The SIEM must support authentication protocols (LDAP, SAML via Okta, Duo, Radius).
The SIEM must support customization of report export templates.
The SIEM must support scheduled report generation.
The SIEM must include a set of reports compliant with international standards such as PCI, CIS, and ISO 27001.
The SIEM must support categorization of assets/event sources.
The SIEM must support collection of streaming telemetry such as NetFlow and sFlow.
The SIEM must support monitoring and alerting on anomalies identified through telemetry analysis.
The SIEM must support deployment of agents on event sources for enhanced logging of Windows and Linux servers.
SIEM agents/collectors must support File Integrity Monitoring (FIM).
SIEM agents/collectors must support User and Entity Behavior Analytics (UEBA).
SIEM agents/collectors must support event buffering in case of loss of connectivity with the central management system.
Email:
TenderAnorbank@anorbank.uz
ANORBANK@exat.uz
Please, introduce yourself to start the conversation