Re: Log Analysis
From: Mattias Hedenskog (tsixla@antisec.net)
Date: 12/03/02
- Previous message: Neal K. Groothuis: "Re: Question on Blocking an ISP."
- In reply to: Niall O Malley (LMI): "Log Analysis"
- Next in thread: Wollenslegel, Troy (T.A.): "RE: Log Analysis"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: Mattias Hedenskog <tsixla@antisec.net> To: "Niall O Malley (LMI)" <Niall.OMalley@eei.ericsson.se>, security-basics@securityfocus.com Date: Tue, 3 Dec 2002 09:08:03 +0100
Hi..
Well that just depends on what service you're refering to? There is a bunch of
them out there.
Personally I prefer ACID(http://acidlab.sourceforge.net) for Snort and
Fireparse(http://aaron.marasco.com/linux.html) for Iptables. The best way to
find out yourself is to look at http://www.freshmeat.net and see for
yourself, thereby get your own opinion.
// Regards
Mattias Hedenskog
> id 76DA3A30C4; Mon, 2 Dec 2002 12:35:35 -0700 (MST)
-- irc:tsixla@efnet,irscnet mail:tsixla@antisec.net http://tsixla.antisec.net g33kcode: AFA0 72DE 73FC F871 7C5F 332D E625 26DB 5025 2057
- Next message: flur: "Re: Can anyone break MD5 scheme?"
- Previous message: Neal K. Groothuis: "Re: Question on Blocking an ISP."
- In reply to: Niall O Malley (LMI): "Log Analysis"
- Next in thread: Wollenslegel, Troy (T.A.): "RE: Log Analysis"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|