As the central nerve center for the Applied Watch Command Center, the Applied Watch Server controls event aggregation, data warehousing, and offers a cost-efficient and scalable solution currently unsurpassed by its competition.
The Applied Watch Server serves as the central repository for all events collected by disparate Applied Watch Agents. Built on open source technology, the Applied Watch Server is powered by the open source PostgreSQL database, allowing for controlled costs of the Applied Watch Server over commercial, more costly database solutions.
Thick Client ReliabilityAs a result of the overwhelming demand for a browserless SNORT® management solution, Applied Watch provides users true real-time performance without the worries of browser refresh delays and cross-browser compatibility issues inherent in other Snort® solutions.
The Applied Watch Command Center is far more than just an alerting tool. The Server provides analysts the capability to also manage the individually supported components by housing the individual configuration files of the supported solutions. Each time configurations are made, geographically dispersed agents connect to the Server to download the latest configurations and apply them to the managed open source tool, such as Snort®
Configuration FlexibilityStaying true to the flexible purchase options Applied Watch offers for its Agent software, the Applied Watch Server is also offered as either a software or hardware appliance purchase, one of many of the hallmark features that Applied Watch has come to be respected for by customers worldwide.
The Applied Watch Server can be managed via a command-line menu system that offers easy configuration and deployment prior to management from the Applied Watch Dashboard. The Server setup menu provides easy access to the PostgreSQL database for command-line purging and other PostgreSQL administration for the advanced user. The user can also view, in real-time, the number of connected Dashboard users and Agents, add and disable users, as well as delete all events in the database. For further n-factor authentication, the Applied Watch Server can also be configured to work with an outside Radius server.
The Applied Watch Server is the central command and control system for the entire Applied Watch Command Center infrastructure. All Applied Watch Agents connect to the Applied Watch Server over TCP port 5150. Dashboard users connect to the Applied Watch Server over TCP port 5150 and 5180. All communication between the Applied Watch Server, Dashboard, and Agents are encrypted in an AES-256 bit encrypted tunnel. Nothing is passed to the Applied Watch Server in clear text.
Most SIM solutions boast thousands of events per minute because they don't log the entire packet, rather, just the packet headers. The Applied Watch Command Center screams at an astounding 1500 events per second -- over 90,000 events per minute, logging the ENTIRE packet! Through use of an internally designed database schema and PostgreSQL, a free, open source database, the Applied Watch Command Center can stand up to the rigors of any enterprise environment and has been tested and proven to be meet the demands of federal, military, and commercial environments around the world.
When configuring a mail server within the Applied Watch Server, the Command Center can be instructed to send email alerts to specific email addresses when predefined criteria are met. Alerts can be defined per IDS signature and suppressed even further by narrowing the email alerts down to specific source and destination IP addresses as well as the number of email alerts sent out.
Whereas most products use proprietary databases, the Applied Watch Server is powered by the open source PostgreSQL database. This allows users to easily create their own scripts to extrapolate data from the Applied Watch Server for their own needs as well as replicate the data to a third party database for redundancy. Use of PostgreSQL also helps keep the costs under control of the Applied Watch Command Center as most companies will rely on Oracle, which can quickly double or triple the price of the product due to expensive licensing.
Applied Watch offers three separate classes of servers that stand up to the rigors of small, large and enterprise/carrier environments. Each Server appliance is hardened and configured for different levels of RAID, each offering differing memory and CPU configurations depending on the number of Agents the Server will be terminating connections from.
The Applied Watch Server appliances are meant to serve organizations wanting to quickly be up and running without the fuss of building their own systems to house the Applied Watch Server software.