special more to read logs

From: @ (richard.lefebvreAROBAS(@)cercaPOINT(.)umontrealPOINT(.)ca)
Date: 03/21/02


From: Richard Lefebvre <richard.lefebvreAROBAS(@)cercaPOINT(.)umontrealPOINT(.)ca>
Date: Thu, 21 Mar 2002 19:09:47 GMT

Hi, I'm looking for a special perpose more (or less, or most) command
to read syslog from a firewall more efficiently. I already split
logs into parts but I still need a bit more. The context is this:
I do a more of the daily SYSLOG checking over stuff, then I get
some hacker that tried to access port AAAAA on every computer
in our network which generates hundreds line in the SYSLOG file
What I do is take a note, stop the more then restart the more
but with an egrep -v "BBB.CCC.DDD.EEE" SYSLOG | more and go
down to the time where I was before and keep on looking, until
the next time I get something else that generate hundreds of
similar lines. I again stop, note then tag an extra host IP to
the egrep and keep on going. The concept of going back to the
top over and over again is ridiculus. So what I would be looking
for is a more with an integrated egrep -v. I have looked at
the man pages of more/less/most but I couldn't find parameters
that would permit me to do an egrep -v on the fly. Does anyone
knows of a tool that will help me do that.

Rick

--
Richard Lefebvre, Sys-admin, CERCA, (514)369-5224            "Don't Panic"
Richard.Lefebvre(@AROBAS)cerca(.POINT)umontreal(.POINT)ca       -- THGTTG
http://www.CERCA.UMontreal.CA/~rick/



Relevant Pages

  • RE: [fw-wiz] (no subject)
    ... There are great tools out there that can read Pix syslog dumps from Kiwi ... such as Reportgen for Pix firewall and also Sawmill. ...
    (Firewall-Wizards)
  • RE: audit trails for file access
    ... I actually use NTSyslog to send my logs off to a syslog server, ... On the syslog server side, I use syslog-ng to log to a MySQL database. ... In regards to logging to another machine, use the Eventlog to Syslog ...
    (Focus-Microsoft)
  • Re: Windows event auditing and reporting
    ... Log to Syslog translators and subsequent Syslog reporting tools. ... Once you get your logs into a generally vendor-agnostic format such as ... Event logs, especially DC logs for events such as New user accounts, ... Computer Emergency Response Teams, and Digital Investigations. ...
    (Security-Basics)
  • RE: advice for syslog server
    ... however watch your CPU usage. ... firewall alone, our Xeon 2.0 HT CPU usually runs at 50% usage on Windows ... great program for a Windows syslog solution. ... Subject: advice for syslog server ...
    (Security-Basics)
  • Re: IPTABLES logging (was: NTP, ntpdate and ISP-based firewall)
    ... > I tell anything kernel* level of syslog to be logged in a file ... > unused syslog level perhaps. ... This is the firewall on the mail server itself; ...
    (Fedora)

Quantcast