Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

ManageEngine: Log360's Re-Engineered Detection Engine Overview

Manage Engine
07/12/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Over 60% are false positives or low-priority noise. And analysts often spend a third of their day investigating them. That not only causes alert fatigue, but delays real threat detection, dissolves context, and also increases risk. And SIEM approaches often overwhelm analysts with noisy alerts and complex rule training. With this recent release in LOCK360, we re-engineered our detection engine to address this issue. Our advanced detection engineering now includes over 2,000 new cloud-delivered security rules that cover anomalies, MITRE-related threats, external malicious threats, true threat intel, and complex correlation use cases. Delivered directly from the cloud, these rules ensure that your detection coverage is always current without the burden of manual updates every now and then. But it shouldn't be just about quantity, right? It should also be about smarter detection. While many SIEMs require deep expertise in proprietary query languages like SPL, KQL, or even AQL to fine-tune rules, LOCK360 makes it simpler. We offer intuitive, analyst-friendly object-level filtering so you can target high-risk assets directly and reduce noise at the source. The result is fewer false positives and more time for your team to focus on real threats. Supporting all of this is LOCK360's enterprise-grade, scalable architecture. As organizations grow and security data explodes across on-premises systems, cloud applications, and even remote endpoints, LOCK360 is designed to keep pace. We now support horizontal scalability with multiple log processor nodes working in parallel. Each node can take on specialized roles like correlation, alerting, or even search for better performance. With a multi-site architecture, logs from distributed locations can be collected and processed centrally. Additional capabilities like high availability and secure gateway support further strengthens resilience and secure connectivity across sites. In short, LOCK360 is enhancing its unified security analytics platform that combines advanced detection, reduced false positives, continuous cloud-delivered content, and a resilient, scalable architecture. All designed to help your security operations center move faster, stay focused, and defend against modern threats with confidence. Discover how LOCK360's 360-degree re-engineered detection can strengthen your security posture today.

TL;DR

  • Log360's re-engineered detection engine addresses alert fatigue by reducing the 60%+ false positive rate that consumes one-third of analyst time daily through smarter filtering and prioritization.
  • The platform delivers over 2,000 cloud-delivered security rules covering MITRE ATT&CK threats, anomalies, threat intelligence, and correlation use cases without requiring manual updates.
  • Unlike traditional SIEMs requiring expertise in proprietary query languages, Log360 offers intuitive object-level filtering to target high-risk assets and reduce noise at the source.

Summary

ManageEngine introduces a re-engineered detection engine for Log360 designed to address the persistent challenge of alert fatigue in security operations. The presentation emphasizes that over 60% of security alerts are false positives or low-priority noise, consuming approximately one-third of analyst time daily. The new detection engine features over 2,000 cloud-delivered security rules covering anomalies, MITRE ATT&CK-mapped threats, external malicious threats, threat intelligence, and complex correlation use cases. Unlike traditional SIEM solutions requiring expertise in proprietary query languages like SPL, KQL, or AQL, Log360 offers intuitive object-level filtering that enables analysts to target high-risk assets directly and reduce noise at the source. The platform's enterprise-grade architecture supports horizontal scalability with multiple log processor nodes working in parallel, each capable of specialized roles including correlation, alerting, and search. Multi-site architecture enables centralized collection and processing of logs from distributed locations, while high availability and secure gateway support strengthen resilience and secure connectivity across sites. The solution positions itself as a unified security analytics platform that combines advanced detection capabilities with reduced false positives, continuous cloud-delivered content updates, and scalable infrastructure to help security operations centers respond faster to modern threats.

Chapters

0:00 - The Alert Fatigue Problem
0:33 - Re-Engineered Detection Engine
1:08 - Smarter Detection Approach
1:43 - Enterprise-Grade Scalability

Key Quotes

0:10 "Over 60% are false positives or low-priority noise."
0:41 "Our advanced detection engineering now includes over 2,000 new cloud-delivered security rules that cover anomalies, MITRE-related threats, external malicious threats, true threat Intel, and complex correlation use cases."
1:14 "While many SIEMs require deep expertise in proprietary query languages like SPL, KQL, or even AQL to fine-tune rules, LOCK360 makes it simpler."

FAQ

How does Log360 reduce false positives compared to traditional SIEM solutions?

Log360 uses intuitive object-level filtering that allows analysts to target high-risk assets directly and reduce noise at the source, rather than requiring complex query language expertise to fine-tune detection rules.

What scalability features does Log360 offer for growing organizations?

Log360 supports horizontal scalability with multiple log processor nodes working in parallel, each capable of specialized roles like correlation, alerting, or search. It also includes multi-site architecture for centralized log collection from distributed locations, plus high availability and secure gateway support.


Categories:
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Security Operations
  • Threat Intelligence
  • Cloud Security
  • Technical Deep Dive
  • Demo
  • SIEM alert fatigue
  • false positive reduction
  • cloud-delivered security rules
  • MITRE ATT&CK mapping
  • object-level filtering
  • horizontal scalability
  • multi-site log collection
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: ManageEngine: Log360's Re-Engineered Detection Engine Overview

              XStreaminars (watch here)

              • Aug
                27

                Becoming Agent Ready with Cyera: Essential Strategies and Insights

                08/27/202601:00 PM ET
                • Sep
                  03

                  Verge.io: Can You Afford Your Next Storage Refresh?

                  09/03/202601:00 PM ET
                  More events

                  Industry Events (Sponsor Hosted)

                  • Aug
                    27

                    Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration

                    08/27/202601:00 PM ET
                    More events

                    Upcoming Webinar Calendar

                    • 08/27/2026
                      01:00 PM
                      08/27/2026
                      Becoming Agent Ready with Cyera: Essential Strategies and Insights
                      https://www.truthinit.com/index.php/channel/2081/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                    • 08/27/2026
                      01:00 PM
                      08/27/2026
                      Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration
                      https://www.truthinit.com/index.php/channel/2086/summer-of-satori-funfonefarms-transformation-of-fraud-into-seamless-integration/
                    • 09/02/2026
                      12:00 PM
                      09/02/2026
                      Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                      https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                    • 09/03/2026
                      01:00 PM
                      09/03/2026
                      Verge.io: Can You Afford Your Next Storage Refresh?
                      https://www.truthinit.com/index.php/channel/2082/verge-io-can-you-afford-your-next-storage-refresh/
                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: Optimizing Visibility and Control in Your Operations
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version