Re: [fw-wiz] (no subject)

From: Tina Bird (tbird_at_precision-guesswork.com)
Date: 03/23/04

  • Next message: Joshua M. Jones: "RE: [fw-wiz] (no subject)"
    To: Hilal Hussein <hilalma@hotmail.com>
    Date: Tue, 23 Mar 2004 10:16:16 -0800 (PST)
    
    

    Hi Hilal --

    On Tue, 23 Mar 2004, Hilal Hussein wrote:

    > But i have two questions concerning this syslog:
    > 1 - the log files are too big since everyfile contains the whole day logs,
    > and since the file size is about 400 + Mb, i am not able to open it. kindly,
    > is there any third party utility which i can use to manage (open, check,
    > filter, ....) the log files of the cisco syslog?
    >
    Before you get into selecting the right tool to do the filtering and
    analysis, you might want to spend a bit of time thinking about what sort
    of events you want to monitor. If you've never looked at system logs
    before, my own personal prejudice is to turn off the network connection
    logging (which is probably what's making your logs so large) and take a
    look at what's generated by administrative events and the like. Get that
    stuff tuned and running so you get the alerts you want, and >then< start
    working with the connection logs.

    I've got a "work in progress" document at:

    http://www.loganalysis.org/sections/parsing/application-specific/firewall-logging.html

    You'll notice that the PIX section is woefully incomplete, but there's a
    lot of good information in there that's platform independent, anyhow.

    [contributions gratefully accepted, especially if anyone wants to write
    something about the PIX]

    > 2 - is there any other syslog server which could work with the cisco pix
    > firewalls, and which is a service and NOT an application?

    I believe you've gotten lots of answers on this one, so I'll repeat my
    main point -- rather than trying to make sense out of what you're being
    handed, you'll get faster results if you think about what you'd like to
    know and go for that...

    And of course, the LogAnalysis mailing list is another resource available
    to you (information on www.loganalysis.org).

    cheers -- tbird

    --
    The only question to which XML is the answer is, "How can I avoid getting
    any work done?"
                                     -- Russ Allbery
    http://www.precision-guesswork.com
    Log Analysis http://www.loganalysis.org
    VPN http://vpn.shmoo.com
    tbird's Security Alerts http://securecomputing.stanford.edu/alert.html
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    

  • Next message: Joshua M. Jones: "RE: [fw-wiz] (no subject)"

    Relevant Pages

    • Re: I dont uderstand ISA Logs
      ... If the logs are written to a SQL database, ... >probably use any proxy you like, ... >unless you build a filter for them, which is very tricky, ... but ISA server have me ...
      (microsoft.public.isa)
    • Re: inbound queue ?
      ... Exchange Server 2007: Managing And Filtering Anti-Spam Agent Logs ... (connection filter, content filter, et al), amongst other things. ...
      (microsoft.public.exchange.admin)
    • Re: Router Firewall with Good Features
      ... We use SafeSquid as proxy and application layer firewall. ... browser basd GUI for management of rules and filters. ... SafeSquid logs can be pumped into mysql database for running different ... Multiple options like url filter, url blacklist, mime filter, cookie ...
      (comp.security.firewalls)
    • Re: simple way to see who and when users are logging in to SBS2K3
      ... Not that I know of - but you can filter the event logs. ... Control Panel. ... SBS Consultant - Canada ...
      (microsoft.public.windows.server.sbs)
    • Re: SBS 2003 into a Syslog server
      ... I need something to filter them. ... I can't seem to find much filtering help in the Free Kiwi program. ... I would like to centralize my logs and make my SBS server a Syslog ...
      (microsoft.public.windows.server.sbs)