Re: Realtime log file anlayser

From: Jeff Cochran (jcochran.nospam@naplesgov.com)
Date: 01/22/03


From: jcochran.nospam@naplesgov.com (Jeff Cochran)
Date: Wed, 22 Jan 2003 13:08:19 GMT


>Well, the idea seems simple, but i dont know if there is a
>software for it yet or maybe i have to write my own.
>I am using URLSCAN to protect my web site -to some extent-
>and when i check the log files of my web server the well
>known attacks have this <rejected-by-urlscan> in their log
>line.
>So what i need is a realtime logfile analyser that when
>faces that phrase in the log line automatically bans-
>permanent or temporary- the ip of the attacker and
>disconnects any session with that IP. So the first
>malicious request will lead to restriction of the access
>from that IP.

Without arguing your assumptions about the effectiveness of this
method, what you want is not a log file analyzer but an intrusion
detection system. Many are available, free to expensive, and can do
what you ask. Search for them in Google, in particular you may
appreciate Snort.

Jeff



Relevant Pages

  • Re: Site Usage Report
    ... >> I do have log files under that location. ... The report does not include data for sites under this Web site. ... >> see detailed data for these sites, see their corresponding usage reports. ... >> For usage information on all sites in this site collection see the Web ...
    (microsoft.public.sharepoint.windowsservices)
  • Can I restrict access to certain IPs?
    ... Thanks Jonathan and Tom for the responses to my other question. ... one company to access our little web site. ... Looking at the log files so far, ...
    (microsoft.public.inetserver.iis.security)
  • Re: More Information than just IIS Log Information
    ... This is generally obtained client side using JavaScript: ... You could then post the information to your web site (for example from the ... be retrieved using IIS Log files. ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Internet Explorer not working
    ... I have done everything like DON said and it worked,i also run the other program which is there on the list,which lets you see what is going on the log files and lets you choose which files you dont want to run, and which you want to remove manually. ... On that Web site from DON they say that our problem is some kind of trojan which dosen't let run or connect to sites with virus scans or add removal tools. ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: My "D" Drive has been removed
    ... use a CD Cleaner on it and clean it. ... I thought it was my Video card so I would just reset the computer and shut ... Ok my D drive on my computer has been removed, I dont know what ... I checked some log files ...
    (microsoft.public.windowsxp.help_and_support)