Re: iptables log analysis tools

From: Chris Travers (chris@travelamericas.com)
Date: 02/24/03

  • Next message: Gene Yoo: "Re: "It's ok we're behind a firewall""
    Date: Mon, 24 Feb 2003 10:51:41 -0800
    From: Chris Travers <chris@travelamericas.com>
    To: Skip Morrow <skip@pelorus.org>
    
    

    Skip Morrow wrote:

    >ACID is great for analyzing snort logs. Are there any good software
    >packages with that kind of power and flexibility for iptables logs?
    >I think one place to start would be to find a way to have iptables
    >log to a mysql database (like snort does).
    >
    >
    There are several tools-- check Sourceforge. For example, there is
    https://sourceforge.net/projects/iptablelog/

    I actually maintain one called fwreport which operates directly on the
    logfiles themselves. While the 1.1.x release is not that flexible
    regarding reporting, the 1.2.x release (due in a week or two) will offer
    extremely powerful reporting capabilities without requiring access to
    databases, etc. Check it out at http://sourceforge.net/projects/fwreport/

    Also if there are any feature requests for fwreport, please feel free to
    submit them ;^)

    Best Wishes,
    Chris Travers



    Relevant Pages

    • Re: iptables log analysis tools
      ... >ACID is great for analyzing snort logs. ... >packages with that kind of power and flexibility for iptables logs? ...
      (Security-Basics)
    • iptables log analysis tools
      ... ACID is great for analyzing snort logs. ... packages with that kind of power and flexibility for iptables logs? ...
      (Security-Basics)
    • Re: Logging network traffic without snort
      ... >> manner but, unfortunately, I cannot stick a snort box in front of my ... But that said, if all you want is a summary of the iptables logs, snort ... here..There's a couple of scripts there to create html summaries of your ...
      (comp.os.linux.security)
    • Re: [fw-wiz] Cisco PIX log analyzer, parser, reporter?
      ... because I was reading through the other thread titled "parsing logs ... some reporting on syslog files. ... simplistic parser would allow you to filter out noise in the logs, ... Collecting iptables logs as ...
      (Firewall-Wizards)