Security Basics mailing list archives

Re: advice for syslog server


From: Michele Jordan <security_lists () michelejordan net>
Date: Fri, 21 Jan 2005 09:52:00 -0500

FM wrote:

Hello,
We are using PIX firewall and I gonna configure an external syslog server.

What do you use to do some automatic log checking ? For example, today a external user downloaded several GB. We saw it on our stats. I cannot look my stats website erveryday for every we server.

So do you know good syslog parser/manager ?

Thanks !


I use fwlogwatch to monitor our iptables logs, I have it mail me reports every morning. A good deal of configurability, it works reasonably well. I believe it supports PIX log formats as well.

-Michele


Current thread: