RE: [fw-wiz] (no subject)

From: Javier Sanchez Llera (jsanchez_at_myalert.com)
Date: 03/23/04

  • Next message: Mitchell Rowton: "Re: [fw-wiz] outbound traffic security risk"
    To: Dean Davis <Dean.Davis@mbg-inc.com>
    Date: Tue, 23 Mar 2004 16:51:38 +0100
    
    

    You should try syslog-ng, it lets you create regexps to store messages
    on different log files, so maybe you can lower the big ones.

    I thing that analog is able to parse/analyze cisco logs coorectly.

    Cheers

    El mar, 23-03-2004 a las 15:19, Dean Davis escribió:
    > Hilal:
    >
    > Consider using Linux, or some Unix variant (FreeBSD, etc.) for Syslog.
    >
    > Windows is an inferior, and bulky platform for this sort of stuff. Syslog is
    > enabled by default in Linux/Unix, and you can parse, and store the data to
    > your heart's content using PERL/Awk/etc. Besides, you'll learn more.
    >
    >
    > Thanks,
    >
    > Dean Davis, MCSE,MCDBA,CCNA,CNA,N+,Linux+
    > Chief Instructor
    > LinuxGenius, LLC.
    > P. 203.543.8979
    > F. 203.286.1983
    > http://www.linuxcbt.net
    >
    >
    >
    > -----Original Message-----
    > From: firewall-wizards-admin@honor.icsalabs.com
    > [mailto:firewall-wizards-admin@honor.icsalabs.com] On Behalf Of Hilal
    > Hussein
    > Sent: Tuesday, March 23, 2004 3:42 AM
    > To: firewall-wizards@honor.icsalabs.com
    > Subject: [fw-wiz] (no subject)
    >
    >
    >
    > Dear List,
    >
    > i have cisco pix firewall that is sending it log data to a cisco syslog
    > server (windowsxp workstation).
    > it is working fine with me since it is a service, so i willl be sure that it
    >
    > is running whenever the server is up and running.
    >
    > But i have two questions concerning this syslog:
    > 1 - the log files are too big since everyfile contains the whole day logs,
    > and since the file size is about 400 + Mb, i am not able to open it. kindly,
    >
    > is there any third party utility which i can use to manage (open, check,
    > filter, ....) the log files of the cisco syslog?
    >
    > 2 - is there any other syslog server which could work with the cisco pix
    > firewalls, and which is a service and NOT an application?
    >
    > your fast respond is highly appreciated,
    >
    > with regards,
    > Hilal
    >
    > _________________________________________________________________
    > MSN 8 with e-mail virus protection service: 2 months FREE*
    > http://join.msn.com/?page=features/virus
    >
    > _______________________________________________
    > firewall-wizards mailing list firewall-wizards@honor.icsalabs.com
    > http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    > _______________________________________________
    > firewall-wizards mailing list
    > firewall-wizards@honor.icsalabs.com
    > http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    >

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Mitchell Rowton: "Re: [fw-wiz] outbound traffic security risk"

    Relevant Pages