Re: [fw-wiz] Reporting Server



On 4/5/07, Eric Anderson <strasser@xxxxxxxxxxxxxxxxxxx> wrote:

I'm interested in what other admins are using for a
reporting server for syslog analysis.

There are two issues here, loosely coupled:
1) Receiving syslog events.
2) Generating reports.

For #1, I prefer to use syslog-ng to accept and filter syslog events.
A free and very flexible syslog daemon, syslog-ng has a commercial
branch coming soon, see http://www.balabit.com/products/syslog_ng/


syslog server receiving packets from a PIX 515E and I want to run reports on IP traffic.

There are a number of free products to parse and report PIX log data,
the first place to start is Marcus Ranum's canonical site,
http://www.loganalysis.org/

One issue with syslog from PIX firewalls is that you either have to
live with the problem of dropped UDP log packets, or live with the TCP
logging "feature" Cisco invented, where the firewall will stop
accepting connections if it can't write to the log server.

Kevin
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: syslog log question
    ... > internet. ... The Sonicwall is configured to send its log information to ... > an internal syslog server. ... reporting mechanism shouldn't have any bearing on whether these ...
    (comp.security.firewalls)
  • Netscreen Logs
    ... reporting for Netscreen. ... Can anyone provide me netscreen (Traffic, event and self deny) logs ... collected by a Syslog? ...
    (comp.security.firewalls)
  • PATCH: Remove unused code from rio_linux.c
    ... - * The following defines are mostly for testing purposes. ... - * some nice reporting in your syslog, ... Prev by Date: ...
    (Linux-Kernel)
  • Re: [fw-wiz] Reporting Server
    ... You can push your syslog entries into the DB using a *nix script, ... I'm interested in what other admins are using for a reporting server for ... I've an Open SUSE 10.2 syslog server receiving packets ... Atheism is a non-prophet organization. ...
    (Firewall-Wizards)
  • Solaris 8 syslog configuration
    ... I have a server which collects syslog events from various other ... If DNS resolution is disabled on this server, ... whenever an external syslog event is received, ...
    (comp.unix.solaris)