Firewall Wizards mailing list archives

Re: WORM file system for logging


From: Carlos Bachmaier <cbachmaier () bigfoot com>
Date: Mon, 03 Aug 1998 19:53:04 +0200

Hi,

Andreas Siegert supposedly wrote:

Hi,
I am desperately looking for a WORM file system for logging purposes.
I want to be able to write to a WORM drive in sort of real time from syslog.
If that is not possible, I'd at leat would like to be able to copy the syslog
file once a day to it and have a reasonable method of retrieving the individual
files.

Should you refer not only to the sw part ...

I had some good experience with the 2.xGB Olympus WORM drive. We used it with
Solaris without major problems to log syslog. It was connected via SCSI, and
Solaris 2.5.1
supported it enoughly well (let aside the formating of the disks ...).

In the states you can purchase a version with unix driver, but the manufacturer in
Europe
was only knowledgeable of PCs ..., so there were (six months ago) either the HW
only
version or the version including the Windows driver ..

A sort of cheap solution is to copy syslog to the serial port, then having an
independent
PC writting the stream to disk, and once every some time to press a CD-ROM.

WORMs disks where some 20 times more expensive that virgin CD-ROMs ... And the
WORM drive costed such as a Pentium plus a CD writing device ...

Of course, the WORM solution is ´cleaner´. One advantage is that syslog is kept
much more
´confidential´, it is not such easy for a simple worker to have access to a reader
;-), and the syslog
might be illegaly used to blackmail some co-workers ... (as would have been taken
from BOFH ...)

If you would already have the HW ... there is a free set of utilities for the a.m.
purpose. Sorry
but lost the pointer, I was a US University project. Try your favorite finder.

Carlos Bachmaier
Wild Thing



Current thread: