Re: Accessing eventlogs remotely & Analysis of them
From: Tevfik Karagülle (tevfik.karagulle_at_computer.org)
Date: 01/13/04
- Previous message: velmurugan.a_at_wartsila.com: "RE: Betr.: Active Directory Question"
- In reply to: Mathew Davies: "Accessing eventlogs remotely & Analysis of them"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: "Mathew Davies" <mathew.davies@ipt-ltd.co.uk>, <focus-ms@securityfocus.com> Date: Tue, 13 Jan 2004 00:25:32 +0100
Hi,
You might consider to have look at my open source project logrep:
http://logrep.sourceforge.net. It can handle eventlogs and is available both
on linux and windows.
Rgrds Tev
----- Original Message -----
From: "Mathew Davies" <mathew.davies@ipt-ltd.co.uk>
To: <focus-ms@securityfocus.com>
Sent: Monday, January 12, 2004 12:18 PM
Subject: Accessing eventlogs remotely & Analysis of them
I use a program to send all our windows systems event to
a central linux syslog server. Currently I run the old
logcheck package on it hourly to try and spot anything
important as well as manual viewing them. But I was
wondering it anyone knew of a better package to run for
the automated analysis of windows events on a linux
syslog server, as logcheck really isn't geared toward it.
This isn't intended to remove the manual review of the logs
just to be a good addition to it and help to spot tends.
-Mat
________________________________________________________________________
This e-mail has been scanned for all viruses by Star Internet. The
service is powered by MessageLabs. For more information on a proactive
anti-virus service working around the clock, around the globe, visit:
http://www.star.net.uk
________________________________________________________________________
---------------------------------------------------------------------------
---------------------------------------------------------------------------
---------------------------------------------------------------------------
---------------------------------------------------------------------------
- Previous message: velmurugan.a_at_wartsila.com: "RE: Betr.: Active Directory Question"
- In reply to: Mathew Davies: "Accessing eventlogs remotely & Analysis of them"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|