Re: XP firewall logs

From: David Chamizo (dchamizo_at_KYOCERA-WIRELESS.COM)
Date: 08/23/04

  • Next message: mikx: "What A Drag! -revisited-"
    Date:         Mon, 23 Aug 2004 11:37:30 -0700
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    Tim-
    The default location of the firewall log can be changed (see link below). I
    agree it would have been nice to see it as an event log. This would also let
    admins forward the logs to a syslog server if needed.

    http://www.informit.com/articles/article.asp?p=28275&seqNum=12

     - Dave

    -----Original Message-----
    From: Windows NTBugtraq Mailing List
    [mailto:NTBUGTRAQ@listserv.ntbugtraq.com] On Behalf Of Tim Chilton -
    Webtribe
    Sent: Tuesday, August 17, 2004 1:10 PM
    To: NTBUGTRAQ@listserv.ntbugtraq.com
    Subject: XP firewall logs

    Does anyone have any ideas why MS decided to put the firewall log files in
    the c:\windows directory as a straight text file rather than using the event
    logs (ie a new firewall log)

    Think the logic through. The OS directory is not supposed to be used for
    temporary files (and I include logs in this). How are we supposed to secure
    the OS areas if it creates logs there !??

    -----
    NTBugtraq Editor's Note:

    Want to reply to the person who sent this message? This list is configured such that just hitting reply is going to result in the message coming to the list, not to the individual who sent the message. This was done to help reduce the number of Out of Office messages posters received. So if you want to send a reply just to the poster, you'll have to copy their email address out of the message and place it in your TO: field.
    -----


  • Next message: mikx: "What A Drag! -revisited-"

    Relevant Pages

    • Re: is someone hacking me?
      ... I see similar entries in our firewall log but we do not allow forwarding to ... Also there's no FTP server running on any of our systems. ... Other stuff that files the firewall logs here are NETBIOS-NS probes. ...
      (comp.os.linux.security)
    • Re: Black Ice and Hackers :-)
      ... In your firewall log, do you ... If your alerts are say at ... Thank you for your concern.Allowed logs show nothing except, ... probably easier) to get into my ISP server and get info on clients from ...
      (comp.security.firewalls)
    • XP firewall logs
      ... Does anyone have any ideas why MS decided to put the firewall log files in ... the c:\windows directory as a straight text file rather than using the event ... include logs in this). ... If event logs were in use, central management via MOM would be possible and ...
      (NT-Bugtraq)
    • Re: pfirewall.log
      ... firewall log to a DIFFERENT filename, ... On our XP machines, we audit the logs pretty regularly since there are 3 XP ... We name the log file MMYY.log on ...
      (microsoft.public.windowsxp.security_admin)
    • Re: logfiles
      ... In the event logs at least. ... But your firewall log should trap ... track access, then you aren't going to be able to track access very ... Jeff ...
      (microsoft.public.windows.server.networking)