Re: advice for syslog server

From: Michele Jordan (security_lists_at_michelejordan.net)
Date: 01/21/05

  • Next message: Johnson, Joey: "RE: I am searching for an good online infosec learning institution.. any suggestions?"
    Date: Fri, 21 Jan 2005 09:52:00 -0500
    To: FM <dist-list@LEXUM.UMontreal.CA>
    
    

    FM wrote:

    > Hello,
    > We are using PIX firewall and I gonna configure an external syslog
    > server.
    >
    > What do you use to do some automatic log checking ? For example, today
    > a external user downloaded several GB. We saw it on our stats. I
    > cannot look my stats website erveryday for every we server.
    >
    > So do you know good syslog parser/manager ?
    >
    > Thanks !
    >
    >
    I use fwlogwatch to monitor our iptables logs, I have it mail me reports
    every morning. A good deal of configurability, it works reasonably
    well. I believe it supports PIX log formats as well.

    -Michele


  • Next message: Johnson, Joey: "RE: I am searching for an good online infosec learning institution.. any suggestions?"