UTMStack

Know every system you monitor, and notice when one goes quiet

UTMStack keeps an inventory of every agent and data source it monitors, with operating system, addresses, status and when it last sent data. Agent-based scans add the software installed on each server and endpoint.

  • Live inventory

    See each agent's host name, IP and MAC addresses, operating system and version, and when it last checked in.

  • Silent sources flagged

    Each source shows as live, idle or offline, with a log timeline and offline counts. A server that stops sending logs does not go unnoticed.

  • Software inventory

    Agent-based scans list installed applications and the libraries inside them, and can produce a software bill of materials.

  • Groups and criticality

    Group sources by site, team or customer, and rate how sensitive each one is for confidentiality, integrity and availability.

  • Context in every alert

    Internal addresses map to departments and how critical they are, so alerts show what kind of system was hit.

Network elements and servers

Every server and endpoint running the UTMStack agent, and every firewall, switch or cloud service sending logs, appears in one list. Network data such as NetFlow and intrusion detection also shows activity from devices that cannot run an agent. Asset data is correlated with the rest of your logs to spot threats, not kept in a separate tool.

Software assets

Software matters as much as hardware. Agent-based scans list what is installed on each server and endpoint and flag outdated or vulnerable versions, so you can act before they are exploited.

Keep sources healthy

A source that stops sending logs is a blind spot, and sometimes the first sign of an attack. UTMStack shows each source's log timeline and offline counts. Agents update themselves and report their status, and forwarder integrations can be switched on or off remotely.

Questions buyers ask

Does UTMStack discover devices automatically?

UTMStack lists every agent and data source that sends it data, and network data such as NetFlow shows other devices talking on your network. It does not run a separate active discovery scan, and the vulnerability scanner only checks the targets you give it.

Can I see installed software?

Yes. Agent-based vulnerability scans on Windows and Linux report installed applications and embedded libraries, and can produce a software bill of materials.

Will I know if a server stops sending logs?

Yes. Each source shows as live, idle or offline based on when it last sent data. The data sources view counts offline sources and shows each one's log timeline.

Protect your organization this week, not next quarter

Talk to an engineer today, or start using UTMStack in minutes.

Need to extend your SOC team?

Our analysts work as an extension of your security team: they cover nights and weekends, take alert overflow and back you up on hard incidents. Book a 30-minute call to plan the coverage you need.

Want to try UTMStack?

Click through the live demo in your browser with no sign-up, start a free cloud instance, or install the open source edition on your own server in about 30 minutes.