I am wondering if native syslog of various firewalls and some proprietary log formats are supported? Is there a method for us to send log samples to see if you can create/include support for those firewalls via patch releases or instructions on how to do it ourselves?
Before looking at this product, I would be interested in having windows event logs, snort logs, watchguard, netscreen firewalls, and sonicwall firewalls be supported in one product - the addition of web type logs (iis and apache) as well as possible anti-virus (mcafee and symantec) would be awesome additions.
Lastly, inclusion of additional intrusion detection/prevention (tippingpoint, mcafee intrushield, snort, etc) would be good too.
To my knowledge a majority of the above products are able to send output to syslog - if you have a syslog collector that could take the data and then input into your system, I think that might be the best way to get max integration?