Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

ManageEngine: Log360's Re-Engineered Detection Engine Overview

Manage Engine
07/12/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Over 60% are false positives or low-priority noise. And analysts often spend a third of their day investigating them. That not only causes alert fatigue, but delays real threat detection, dissolves context, and also increases risk. And SIEM approaches often overwhelm analysts with noisy alerts and complex rule training. With this recent release in LOCK360, we re-engineered our detection engine to address this issue. Our advanced detection engineering now includes over 2,000 new cloud-delivered security rules that cover anomalies, MITRE-related threats, external malicious threats, true threat intel, and complex correlation use cases. Delivered directly from the cloud, these rules ensure that your detection coverage is always current without the burden of manual updates every now and then. But it shouldn't be just about quantity, right? It should also be about smarter detection. While many SIEMs require deep expertise in proprietary query languages like SPL, KQL, or even AQL to fine-tune rules, LOCK360 makes it simpler. We offer intuitive, analyst-friendly object-level filtering so you can target high-risk assets directly and reduce noise at the source. The result is fewer false positives and more time for your team to focus on real threats. Supporting all of this is LOCK360's enterprise-grade, scalable architecture. As organizations grow and security data explodes across on-premises systems, cloud applications, and even remote endpoints, LOCK360 is designed to keep pace. We now support horizontal scalability with multiple log processor nodes working in parallel. Each node can take on specialized roles like correlation, alerting, or even search for better performance. With a multi-site architecture, logs from distributed locations can be collected and processed centrally. Additional capabilities like high availability and secure gateway support further strengthens resilience and secure connectivity across sites. In short, LOCK360 is enhancing its unified security analytics platform that combines advanced detection, reduced false positives, continuous cloud-delivered content, and a resilient, scalable architecture. All designed to help your security operations center move faster, stay focused, and defend against modern threats with confidence. Discover how LOCK360's 360-degree re-engineered detection can strengthen your security posture today.

TL;DR

  • Log360's re-engineered detection engine addresses alert fatigue by reducing the 60%+ false positive rate that consumes one-third of analyst time daily through smarter filtering and prioritization.
  • The platform delivers over 2,000 cloud-delivered security rules covering MITRE ATT&CK threats, anomalies, threat intelligence, and correlation use cases without requiring manual updates.
  • Unlike traditional SIEMs requiring expertise in proprietary query languages, Log360 offers intuitive object-level filtering to target high-risk assets and reduce noise at the source.

Summary

ManageEngine introduces a re-engineered detection engine for Log360 designed to address the persistent challenge of alert fatigue in security operations. The presentation emphasizes that over 60% of security alerts are false positives or low-priority noise, consuming approximately one-third of analyst time daily. The new detection engine features over 2,000 cloud-delivered security rules covering anomalies, MITRE ATT&CK-mapped threats, external malicious threats, threat intelligence, and complex correlation use cases. Unlike traditional SIEM solutions requiring expertise in proprietary query languages like SPL, KQL, or AQL, Log360 offers intuitive object-level filtering that enables analysts to target high-risk assets directly and reduce noise at the source. The platform's enterprise-grade architecture supports horizontal scalability with multiple log processor nodes working in parallel, each capable of specialized roles including correlation, alerting, and search. Multi-site architecture enables centralized collection and processing of logs from distributed locations, while high availability and secure gateway support strengthen resilience and secure connectivity across sites. The solution positions itself as a unified security analytics platform that combines advanced detection capabilities with reduced false positives, continuous cloud-delivered content updates, and scalable infrastructure to help security operations centers respond faster to modern threats.

Chapters

0:00 - The Alert Fatigue Problem
0:33 - Re-Engineered Detection Engine
1:08 - Smarter Detection Approach
1:43 - Enterprise-Grade Scalability

Key Quotes

0:10 "Over 60% are false positives or low-priority noise."
0:41 "Our advanced detection engineering now includes over 2,000 new cloud-delivered security rules that cover anomalies, MITRE-related threats, external malicious threats, true threat Intel, and complex correlation use cases."
1:14 "While many SIEMs require deep expertise in proprietary query languages like SPL, KQL, or even AQL to fine-tune rules, LOCK360 makes it simpler."

FAQ

How does Log360 reduce false positives compared to traditional SIEM solutions?

Log360 uses intuitive object-level filtering that allows analysts to target high-risk assets directly and reduce noise at the source, rather than requiring complex query language expertise to fine-tune detection rules.

What scalability features does Log360 offer for growing organizations?

Log360 supports horizontal scalability with multiple log processor nodes working in parallel, each capable of specialized roles like correlation, alerting, or search. It also includes multi-site architecture for centralized log collection from distributed locations, plus high availability and secure gateway support.


Categories:
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Security Operations
  • Threat Intelligence
  • Cloud Security
  • Technical Deep Dive
  • Demo
  • SIEM alert fatigue
  • false positive reduction
  • cloud-delivered security rules
  • MITRE ATT&CK mapping
  • object-level filtering
  • horizontal scalability
  • multi-site log collection
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: ManageEngine: Log360's Re-Engineered Detection Engine Overview

              Upcoming 360 View Events

              • Nov
                19

                360View: Govern, Secure & Recover Your Microsoft 365 Environment

                11/19/202601:00 PM ET
                More events

                XStreaminars (watch here)

                • Oct
                  28

                  EnvZero: Near-Zero Time to Resolution--Live Agentic Remediation for Failed and Drifted Infrastructure

                  10/28/202601:00 PM ET
                  More events

                  Industry Events (Sponsor Hosted)

                  • Oct
                    13

                    Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance

                    10/13/202601:00 PM ET
                    • Oct
                      15

                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                      10/15/202611:00 AM ET
                      • Oct
                        20

                        Harnessing Data Governance for AI with Cyera and Snowflake

                        10/20/202611:00 AM ET
                        • Oct
                          27

                          Maximize Security, Value, and Returns on Your Microsoft Investment

                          10/27/202611:00 AM ET
                          • Oct
                            27

                            The HUMAN Experience: Real-Time Insights into Page Intelligence

                            10/27/202601:00 PM ET
                            More events

                            Upcoming Webinar Calendar

                            • 10/13/2026
                              01:00 PM
                              10/13/2026
                              Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance
                              https://www.truthinit.com/index.php/channel/2159/transitioning-from-cjis-to-ferpa-essential-audit-evidence-for-compliance/
                            • 10/15/2026
                              11:00 AM
                              10/15/2026
                              Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                              https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                            • 10/20/2026
                              11:00 AM
                              10/20/2026
                              Harnessing Data Governance for AI with Cyera and Snowflake
                              https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                            • 10/27/2026
                              11:00 AM
                              10/27/2026
                              Maximize Security, Value, and Returns on Your Microsoft Investment
                              https://www.truthinit.com/index.php/channel/2178/maximize-security-value-and-returns-on-your-microsoft-investment/
                            • 10/27/2026
                              01:00 PM
                              10/27/2026
                              The HUMAN Experience: Real-Time Insights into Page Intelligence
                              https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                            • 10/28/2026
                              01:00 AM
                              10/28/2026
                              [APAC:] Secure AI Everywhere: Visibility, governance and protection for the agentic era
                              https://www.truthinit.com/index.php/channel/2125/apac-ensuring-comprehensive-security-for-ai-applications/
                            • 10/28/2026
                              06:00 AM
                              10/28/2026
                              [EMEA:] Secure AI Everywhere: Visibility, governance and protection for the agentic era
                              https://www.truthinit.com/index.php/channel/2127/emea-ensuring-ai-security-across-all-platforms/
                            • 10/28/2026
                              01:00 PM
                              10/28/2026
                              [AMERICAS:] Secure AI Everywhere: Visibility, governance and protection for the agentic era
                              https://www.truthinit.com/index.php/channel/2126/securing-ai-across-the-americas-strategies-and-insights/
                            • 10/28/2026
                              01:00 PM
                              10/28/2026
                              EnvZero: Near-Zero Time to Resolution--Live Agentic Remediation for Failed and Drifted Infrastructure
                              https://www.truthinit.com/index.php/channel/2179/envzero-near-zero-time-to-resolution-live-agentic-remediation-for-failed-and-drifted-infrastructure/
                            • 11/04/2026
                              11:00 AM
                              11/04/2026
                              Leveraging CISA’s Zero Trust Maturity Model in an AI-Driven Landscape
                              https://www.truthinit.com/index.php/channel/2149/leveraging-cisas-zero-trust-maturity-model-in-an-ai-driven-landscape/
                            • 11/04/2026
                              11:00 AM
                              11/04/2026
                              Aligning Agentic Intent: Understanding Your Agents' Purpose vs. Their Actions
                              https://www.truthinit.com/index.php/channel/2158/aligning-agentic-intent-understanding-your-agents-purpose-vs-their-actions/
                            • 11/05/2026
                              02:00 PM
                              11/05/2026
                              HUMAN Dialogue: Embracing the Rise of the Agentic Consumer in AI
                              https://www.truthinit.com/index.php/channel/2160/human-dialogue-embracing-the-rise-of-the-agentic-consumer-in-ai/
                            • 11/05/2026
                              02:00 PM
                              11/05/2026
                              Reclaim Your Evenings: Leverage Data Intelligence to Minimize Risk and Boost AI Adoption
                              https://www.truthinit.com/index.php/channel/2172/reclaim-your-evenings-leverage-data-intelligence-to-minimize-risk-and-boost-ai-adoption/
                            • 11/19/2026
                              01:00 PM
                              11/19/2026
                              360View: Govern, Secure & Recover Your Microsoft 365 Environment
                              https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                            Truth in IT
                            • Sponsor
                            • About Us
                            • Terms of Service
                            • Privacy Policy
                            • Contact Us
                            • Preference Management
                            Desktop version
                            Standard version