Re: Log analyzer

From: Hugo van der Kooij (hvdkooij@vanderkooij.org)
Date: 01/09/02


Date: Wed, 9 Jan 2002 23:06:21 +0100 (CET)
From: Hugo van der Kooij <hvdkooij@vanderkooij.org>
To: Focus on Linux Mailing List <focus-linux@securityfocus.com>

On Wed, 9 Jan 2002, Jerome Tytgat wrote:

> I need help in using or finding a good log analyzer.
>
> Logwatch is shipped with redhat 7.2 but I want to use it
> to analyze /var/log/kernel, /var/log/snort/*,
> /var/log/message[snort:]. But I can't find any scripts for
> snort for logwatch.

You need snortsnarf!

Hugo.

-- 
All email send to me is bound to the rules described on my homepage.
    hvdkooij@vanderkooij.org		http://hvdkooij.xs4all.nl/
	    Don't meddle in the affairs of sysadmins,
	    for they are subtle and quick to anger.