Re: [fw-wiz] parsing logs ultra-fast inline



All,

While I am preparing to enter this discussion in full force :-), I
figured I'd shoot a quick one on this:

meaning. Take Tina's VPN example - how many types of log entries you would
expect from a VPN concentrator? From my experience, not more than 20 but
let's assume there are 50. Give a sample from each entry to a Perl

He-he, no :-) I just looked at the old documentation bundle of Cisco
VPN 3000 messages and its nowhere near the above. How about 2049
unique messages documented by Cisco?

Parsing IS often a challenge, e.g. see this and the discussion that
ensued: http://airsnarf.shmoo.com/pipermail/loganalysis/2005-December/002906.html

Syslog is where it becomes just plain extreme (50,000 message types
anybody?), as Marcus pointed out, but there are some other fun areas
where it is tough.

Best,
--
Anton Chuvakin, Ph.D., GCIA, GCIH, GCFA
http://www.chuvakin.org
http://www.securitywarrior.com
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxx
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: vpnc on FreeBSD 6.2
    ... I am trying to make vpnc working on my FreeBSD 6.2 laptop to connect to a Cisco ... 3000 VPN concentrator without any luck. ... I just recently colaborated with a co-worker in getting vpnc working on our non-Windoes machines. ...
    (freebsd-questions)
  • Re: Cisco Secure ACS vs. Firewall
    ... Good points about the Cisco 3000 VPN Concentrator. ... mentioning about the *firewall* is that the VPN3K does basic NAT/Port ... RE>>on the company LAN is. ...
    (Security-Basics)
  • 3005 VPN does not respond on console port
    ... I have a CISCO 3005 VPN Concentrator that came back from a site we shut ... I have no passwords for this device. ... blinking cursor. ...
    (comp.dcom.vpn)
  • Re: Alternative for cisco vpn concentrator
    ... Even though Cisco has discontinued the VPN concentrator series, ... model devices. ...
    (comp.dcom.sys.cisco)
  • RE: [fw-wiz] parsing logs ultra-fast inline
    ... figured I'd shoot a quick one on this: ... would expect from a VPN concentrator? ... no :-) I just looked at the old documentation bundle of Cisco ... starting out) is the source of an inbound remote access connection, ...
    (Firewall-Wizards)