Logit.io

We enable companies to achieve compliance with many leading standards

  • PCI-DSS

    PCI-DSS

  • HIPAA

    HIPAA

  • FISMA

    FISMA

  • SOX

    SOX

  • GLBA

    GLBA

  • ISO 27001:2022

    ISO 27001:2022

Solutions

CIS Compliance Tool

Experience centralised CIS Compliance for audit logs and other types of telemetry

observability stack
Ingest
Correlate
Visualize
Act
Logs
Logstash · OpenSearch
12.4k/s
Metrics
Prometheus · Grafana
10k series
APM
OTLP · traces
p95 84ms
--:--:-- INFO request.completed duration_ms=42 route="/api/v1/orders"
--:--:-- WARN latency.spike service=checkout p95=820ms threshold=500ms
--:--:-- INFO trace.exported spans=128 backend=jaeger status="ok"
--:--:-- INFO metric.scrape target=prometheus job=k8s-pods samples=8421
--:--:-- INFO log.shipped bytes=184032 index=logs-prod
--:--:-- WARN auth.failure ip=203.0.113.42 attempts=3 action=rate_limit
--:--:-- INFO alert.routed severity=high channel="#incidents" dedupe=on
--:--:-- INFO dashboard.refresh uid=ops-overview panels=14 cache=hit
--:--:-- ERROR disk.pressure node=worker-3 usage=92% reclaim=started
--:--:-- INFO pipeline.batch size=2048 lag_ms=18 status=healthy
--:--:-- WARN queue.backpressure topic=ingest depth=1200
--:--:-- INFO otel.export endpoint=collector.svc spans_ok=512
--:--:-- INFO search.query hits=1284 took_ms=37 index=logs-*
--:--:-- INFO retention.policy applied hot=14d warm=30d
--:--:-- WARN tls.cert.expiring host=ingest.logit.io days=12
--:--:-- INFO ha.failover check region=eu-west status=ready
--:--:-- INFO request.completed duration_ms=42 route="/api/v1/orders"
--:--:-- WARN latency.spike service=checkout p95=820ms threshold=500ms
--:--:-- INFO trace.exported spans=128 backend=jaeger status="ok"
--:--:-- INFO metric.scrape target=prometheus job=k8s-pods samples=8421
--:--:-- INFO log.shipped bytes=184032 index=logs-prod
--:--:-- WARN auth.failure ip=203.0.113.42 attempts=3 action=rate_limit
--:--:-- INFO alert.routed severity=high channel="#incidents" dedupe=on
--:--:-- INFO dashboard.refresh uid=ops-overview panels=14 cache=hit
--:--:-- ERROR disk.pressure node=worker-3 usage=92% reclaim=started
--:--:-- INFO pipeline.batch size=2048 lag_ms=18 status=healthy
--:--:-- WARN queue.backpressure topic=ingest depth=1200
--:--:-- INFO otel.export endpoint=collector.svc spans_ok=512
--:--:-- INFO search.query hits=1284 took_ms=37 index=logs-*
--:--:-- INFO retention.policy applied hot=14d warm=30d
--:--:-- WARN tls.cert.expiring host=ingest.logit.io days=12
--:--:-- INFO ha.failover check region=eu-west status=ready
+ one managed platform
+ peak overage protection
! bundle up to 30% off

Trusted by engineering teams worldwide

Maersk
Murphy
Ringier
GDS
Guesty
HackerRank
Equal Experts
DevEx
Digitale Medier
xneelo
CAA
Pivotal
Robomed Network
Neoway
Gomo Learning
Department for BEIS
IBM
Broad Institute
The Honest Company
Traels
De Banke
Dofinity
BioCatch
Kainos
Youredi
Flux Music
Goji
Ving
HypSports
Boston Logic
Double Jump
Log management
from$25/mo

Annual billing · 14-day free trial

View pricing plans

Why You Should Comply With CIS

In the past few years, there have been numerous examples of how poorly configured systems have paved the way for hackers. These examples have also led to regulatory bodies imposing hefty fines for improper conduct.

Fortunately, there are prescriptive guidelines, provided by the Center for Internet Security (CIS), for establishing a secure baseline configuration for assets to prevent poorly implemented configurations. CIS Benchmarks are the only independent, consensus-based, and industry-accepted guidelines for configuration best practices that have been developed by a global community of cybersecurity professionals and academics from all walks of life and are accepted by governments, businesses, industries, and the wider academic community.

If you want to manually assess all your endpoints, network devices and operating systems within a highly distributed system architecture, it is worth knowing that these benchmarks run about 800 pages on average and make over 300 recommendations within them. With all of these guidelines to comply with a solution that can meet at least ten of these controls can save your engineers many hours from having to manually centralise data.

As a result, The Logit.io platform has become an essential tool in the vulnerability management process for centralising logs, events and traces. Monitor your endpoints for any CIS control violations and make corrective actions in real time by leveraging the Logit.io CIS compliance solution. With Logit.io‘s extensive CIS compliance features, the platform can be used to meet various critical controls including 8.1, 8.2, 8.3, 8.5, 8.6, 8.7, 8.8, 8.9, 8.10, 8.11 and 8.12.

pipeline
Ingest
Parse
Index
Query
+streams normalized · schema applied
output ready for search, alerts, and dashboards

What Are CIS Benchmarks?

The Center of Internet Security (CIS) Benchmarks are a set of globally recognized and consensus-driven best practices that provide guidance and assistance to security practitioners in the implementation, management, and enhancement of their cybersecurity defences.

These CIS benchmarks were developed with help from a global community of security experts in order to help organisations take proactive measures to safeguard themselves against emerging threats. It‘s important that companies use the CIS benchmark guidelines in order to limit configuration-based security vulnerabilities in their digital assets.

stream
--:--:-- INFO request.completed duration_ms=42 route="/api/v1/orders"
--:--:-- WARN latency.spike service=checkout p95=820ms threshold=500ms
--:--:-- INFO trace.exported spans=128 backend=jaeger status="ok"
--:--:-- INFO metric.scrape target=prometheus job=k8s-pods samples=8421
--:--:-- INFO log.shipped bytes=184032 index=logs-prod
--:--:-- WARN auth.failure ip=203.0.113.42 attempts=3 action=rate_limit
--:--:-- INFO alert.routed severity=high channel="#incidents" dedupe=on
--:--:-- INFO dashboard.refresh uid=ops-overview panels=14 cache=hit
--:--:-- ERROR disk.pressure node=worker-3 usage=92% reclaim=started
--:--:-- INFO pipeline.batch size=2048 lag_ms=18 status=healthy
--:--:-- WARN queue.backpressure topic=ingest depth=1200
--:--:-- INFO otel.export endpoint=collector.svc spans_ok=512
--:--:-- INFO search.query hits=1284 took_ms=37 index=logs-*
--:--:-- INFO retention.policy applied hot=14d warm=30d
--:--:-- WARN tls.cert.expiring host=ingest.logit.io days=12
--:--:-- INFO ha.failover check region=eu-west status=ready
--:--:-- INFO request.completed duration_ms=42 route="/api/v1/orders"
--:--:-- WARN latency.spike service=checkout p95=820ms threshold=500ms
--:--:-- INFO trace.exported spans=128 backend=jaeger status="ok"
--:--:-- INFO metric.scrape target=prometheus job=k8s-pods samples=8421
--:--:-- INFO log.shipped bytes=184032 index=logs-prod
--:--:-- WARN auth.failure ip=203.0.113.42 attempts=3 action=rate_limit
--:--:-- INFO alert.routed severity=high channel="#incidents" dedupe=on
--:--:-- INFO dashboard.refresh uid=ops-overview panels=14 cache=hit
--:--:-- ERROR disk.pressure node=worker-3 usage=92% reclaim=started
--:--:-- INFO pipeline.batch size=2048 lag_ms=18 status=healthy
--:--:-- WARN queue.backpressure topic=ingest depth=1200
--:--:-- INFO otel.export endpoint=collector.svc spans_ok=512
--:--:-- INFO search.query hits=1284 took_ms=37 index=logs-*
--:--:-- INFO retention.policy applied hot=14d warm=30d
--:--:-- WARN tls.cert.expiring host=ingest.logit.io days=12
--:--:-- INFO ha.failover check region=eu-west status=ready

Centralising Audit Logs

It is generally accepted that there are two types of logs that are treated and configured independently: system logs and audit logs. Typically, system log files provide information on a system-level basis, such as when the system processes started or stopped, and when crashes occurred. This type of logging is native to the system, so it requires less configuration in order to be turned on. Typically, audit logs cover events that occur at the user level, events such as a user logging in or accessing a file. These require a greater amount of planning and effort before they can be set up for analysis.

Having a record of all log entries is crucial for responding to incidents when they occur. Immediately after an attack has been detected, enterprises may be able to gain a better understanding of the extent of the attack by analysing log files. When you maintain detailed log records, you will also be able to identify when and how the attack occurred, what information was accessed, and if any data was exfiltrated, for example. Furthermore, retaining log files is crucial in the case that a follow-up investigation is required or in the case that a long period of time elapsed before an attack was detected.

shell
$
logit trace export --protocol=otlp --backend=jaeger
→ distributed spans indexed · p99=84ms

Logit.io CIS Audit Log Solution

With Logit.io's extensive CIS compliance features, the platform can be used to meet various critical controls including 8.1, 8.2, 8.3, 8.5, 8.6, 8.7, 8.8, 8.9, 8.10, 8.11 and 8.12.

As a means of achieving compliance by implementing CIS Benchmarks, Logit.io can be configured to generate compliance dashboards which are direct derivatives of the official benchmarks themselves. These are required to audit your systems‘ configurations successfully and to ensure that a system is configured in a manner that meets the security standards recommended in CIS benchmarks.

It is essential for enterprises to collect and analyse logs in order to be able to detect malicious activities in a timely manner. Audit log records are sometimes the only proof that a breach has occurred. It is well known by attackers that while enterprises store audit logs in order to comply with regulations, they rarely analyse them for compliance purposes. As a result of poor or ineffective log analysis processes, attackers are sometimes able to sustain control over machines remotely for many months without anyone within the enterprise knowing about the infiltration.

metrics
latency
throughput
errors
p95 latency 84ms · ingest 12.4k/s · error rate 0.08%

Avoid The Need For Expensive SIEM

In previous versions of the CIS benchmarks, it was recommended to deploy a SIEM tool to centrally manage audit logs. This advice has since been redacted due to the fact that organisations may be able to meet CIS controls by using a centralised log management service instead.

According to the most recent guidelines, CIS practitioners are now taking steps to not be too prescriptive regarding which tools should be used to ensure compliance. You can avoid using a SIEM solution that might be more complex than what is needed to meet CIS benchmarks by regularly reviewing your logs.

If long retention periods are required, it may very well be cheaper to use cold cloud storage (such as Amazon S3). Logit.io offers users the option to store audit logs for long-term retention within hosted S3 deployments as part of its solution.

Logit.io provides an affordable solution to meet many of the CIS controls because it offers robust data storage, alerting, and support for using a variety of query expression languages. When these basics are all covered, this alone will meet many guidelines for running a CIS compliant system.

alerts
1
Detect
2
Enrich
3
Route
4
Notify
! anomaly detected · checkout p95 > 500ms
→ context attached · service map · recent deploy
→ routed to #incidents · ack in 12s

Security and Compliance

As Logit.io puts the security and privacy of your operational data at the top of its priority list in all of our systems, you‘ll be glad to know that we are ISO certified and audited by UKAS. Moreover, we comply with GDPR, HIPAA and SOC2 along with being PCI DSS compliant as well.

Read all security standards
stack
OpenSearchPrometheusGrafanaJaegerLogstash
$ logit stack status --managed
all services healthy · HA enabled · backups current

Demonstrate CIS Compliance With The Following Controls:

  • 8.1: Establish and Maintain an Audit Log Management Process
  • 8.2: Collect Audit Logs
  • 8.3: Ensure Adequate Audit Log Storage
  • 8.5: Collect Detailed Audit Logs
  • 8.6: Collect DNS Query Audit Logs
  • 8.7: Collect URL Request Audit Logs
  • 8.8: Collect Command-Line Audit Logs
  • 8.9: Centralize Audit Logs
  • 8.10: Retain Audit Logs
  • 8.11: Conduct Audit Log Reviews
  • 8.12: Collect Service Provider Logs
  • pipeline
    Ingest
    Parse
    Index
    Query
    +streams normalized · schema applied
    output ready for search, alerts, and dashboards

    Companies Feel The Difference When They Use Logit.io

    Internally, Logit.io has made it easier for us to provide better support for our customers, since finding individual messages based on various data in the payload has become easier.

    At Youredi, pretty much everyone from our technical support teams through to our professional services teams uses Logit.io.

    Youredi

    Mats von Weissenberg

    CTO @ Youredi

    Start your 14-day free trial

    No credit card required. Managed OpenSearch, Prometheus, and Grafana from $25/mo.