Re: Aggregating logs from numerous FreeBSD machines

From: Chuck Swiger (cswiger_at_mac.com)
Date: 01/13/05

  • Next message: Eric Anderson: "Re: Aggregating logs from numerous FreeBSD machines"
    Date: Thu, 13 Jan 2005 13:43:40 -0500
    To: Mark Johnston <mjohnston@skyweb.ca>
    
    

    Mark Johnston wrote:
    > If I had to imagine an ideal system, it would be a central server that
    > securely collects syslog messages from all my servers, indexes them by server
    > and severity, and gives a reasonable management interface. Given expressions
    > based on facility, severity, log message, and the like, it could throw away
    > useless messages, or page me for critical ones. This would tie into
    > AIDE/Samhain/Tripwire (haven't picked one yet) and maybe even different
    > flavors of IDS. It could even warn me when processes run away with the CPU
    > or RAM, or disks get too full.

    Consider Big Brother from www.bb4.com. It monitors processes, ports, disk
    space, load average, looks for interesting stuff in the system logfile, and
    has a central web-based dashboard with historical logs.

    [ Slightly off-topic for freebsd-security, moving to -questions. ]

    -- 
    -Chuck
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    

  • Next message: Eric Anderson: "Re: Aggregating logs from numerous FreeBSD machines"

    Relevant Pages

    • Re: [SLE] Machine Building - Nightmare Alley - Compatibility and Upgrade
      ... On the other side I've been using Gigabyte boards with SuSE for years no ... graphic cards as the server terminal stays in text mode anyway. ... > department) that I will have to install their SuSe 9.1 distribution from ... Disks have a limited life time... ...
      (SuSE)
    • Re: Unix runs faster, maybe (was: Re: Educating potential VMS users)
      ... That's what I just suggested, Kerry: they're limited by disk I/O, not CPU, and hence CPU utilization *will* be low, even if the disks are working their little tails off. ... A server with very low CPU utilization is a *good* candidate for virtualization, since it's got lots of horsepower left over for other tasks that admins might be reluctant to run on the same OS instance: just hook up some more disks to service the added applicationand let 'er rip. ...
      (comp.os.vms)
    • Re: panic after removing usb flash disk
      ... are only interested in it for its use as a server or embedded OS. ... they 1) stopped using single disks in their multi-thousand-dollar ... ATA disks with no hotswap capability. ... I have no idea whether Juniper is a contributor to FreeBSD. ...
      (freebsd-stable)
    • Re: PowerEdge 1800 Spontaneous Reboots
      ... you're seeing the server crashing? ... I thought it could be the raid controller, but no HDD are attached to ... RAID 1 Mirror array spanning the whole of the 160GB. ... rebuilding the MBR or BOOT record with both disks plugged into the ...
      (microsoft.public.windows.server.sbs)
    • Re: Exchange Disks
      ... I was looking at using a cheaper alternative with 7,200 RPM Server SATA ... Logs raid 1 mirror ... consider single drives for the OS and or Logs instead of mirrors. ... Is there some sort of rule-of-thumb for setting up disks based on a number ...
      (microsoft.public.exchange.setup)