Re: [fw-wiz] Centrallizing logs

From: Rudy_D_Pereda@mail.dbf.state.fl.us
Date: 09/12/02


To: m p <sumirati@yahoo.de>, firewall-wizards@nfr.com, firewall-wizards-admin@honor.icsalabs.com, Rudy_D_Pereda@mail.dbf.state.fl.us
From: Rudy_D_Pereda@mail.dbf.state.fl.us
Date: Thu Sep 12 15:39:01 2002

MP,
Couldn't be that lucky, we still run IIS(4). On the NT side, have you used
any software to redirect NT event logs to a syslog server?

And thanks for your 2 cents. much appreciated.

rdp

|---------+---------------------------->
| | m p |
| | <sumirati@yahoo.d|
| | e> |
| | |
| | 09/12/2002 03:20 |
| | PM |
| | |
|---------+---------------------------->
>--------------------------------------------------------------------------------------------------------------------------------------------------|
  | |
  | To: Rudy_D_Pereda@mail.dbf.state.fl.us, firewall-wizards@nfr.com, firewall-wizards-admin@honor.icsalabs.com |
  | cc: |
  | Subject: Re: [fw-wiz] Centrallizing logs |
>--------------------------------------------------------------------------------------------------------------------------------------------------|

 --- Rudy_D_Pereda@mail.dbf.state.fl.us schrieb: >
> I would like to centralize my logs to one server. The OS that I would be
> using would be FreeBSD 4.6. My environment consists of cisco
> routers/firewalls, freebsd running ipfilter and web servers running on
NT.
> I have two questions: 1) What syslog do you recommend?, 2) what software
do
> you recommend to check logs?
>
> Any info will be much appreciated,
>
> thanks to all in advance,
>
> rdp
>
>

As for the ciscos: They report all things via syslog.
As for ipfilter on FreeBSD: Via ipmon you can utilize syslog.
As for the web servers: Which one are you running? Apache can be talked
into to
 log via syslog. I checked for IIS 4 (we are still running some of them
here
*sigh*) - it can of course not log to anything else then to a file. Perhaps
IIS
5 can do it - or you are not running IIS at all (if you are lucky).

For the questions:
1) I'm not a code monkey anymore. That was some years back in time ;). But
the
functionality and handling of syslog-ng is ok for me. The quality of the
code
is better approved by someone else.
2) Analog is quite handy. Originaly it is a web server log analyser. Some
people wrote scripts that you can analyse your
ipf/BIND/sendmail/qmail/postfix
as if they were web logs. Or you write your own script to convert your logs
to
what you want. Or use Perl and time to create a log tool to match _your_
requirements. The requierements may differ extremly.

Just my 2 cent.

Marc

__________________________________________________________________

Gesendet von Yahoo! Mail - http://mail.yahoo.de
Möchten Sie mit einem Gruß antworten? http://grusskarten.yahoo.de



Relevant Pages

  • RE: Need to implemet Syslog server
    ... If you need a Windows based syslog. ... On my network I need to implement a Syslog server which will need to log ... assuming I have many servers (15-20 servers to take logs from) ...
    (Security-Basics)
  • Re: Prelude/OSSIM/OpenSIMS/OSSEC
    ... I have a similar topology developed with OSSIM like the one you are lookig for. ... OSSIM server, and Integrity, checked by OSIRIS, that are manage by a ... The windows Machines, Windows 2000 Servers and XP, send the logs to ... the same syslog server by a tool called ...
    (Focus-IDS)
  • Re: [SLE] Scanned, hacked, or what?
    ... single proffessional who might like to have the control over thier own ... like the logs and apparent scans and attacks, ... I try to explain that an ill created "web server" which, ... month or two investigating web servers and thier setup (which still ...
    (SuSE)
  • RE: audit trails for file access
    ... I actually use NTSyslog to send my logs off to a syslog server, ... On the syslog server side, I use syslog-ng to log to a MySQL database. ... In regards to logging to another machine, use the Eventlog to Syslog ...
    (Focus-Microsoft)
  • Re: Windows event auditing and reporting
    ... Log to Syslog translators and subsequent Syslog reporting tools. ... Once you get your logs into a generally vendor-agnostic format such as ... Event logs, especially DC logs for events such as New user accounts, ... Computer Emergency Response Teams, and Digital Investigations. ...
    (Security-Basics)