Firewall Wizards mailing list archives

Log monitoring / alerting


From: Jean Caron <caronj () norac net>
Date: Thu, 5 Oct 2000 13:05:06 -0400 (EDT)


Hi folks,

I'm sure the question has been asked many times over, yet I don't know
the answer.

I'm looking for a tool, or combination of tools, that can analyze, report
and send alarms based on log files data coming from PIX, Solaris (running
firewall), etc.

As for a quick glance at requirements;

- accept logs from multipls hosts (100s),
- Produce alarms based on syslog messages,
- Distribute alarms via emails, pager, snmp traps, programs calls, etc.
- Detect and log system reboots,
- Alarm if/when logging stops from a certain node,

...just to name a few.

I'm already aware of several such tools out there, but so far, none seem
to do it all, or do it all well.

Any suggestions would be greatly appreciated.

Jean


_______________________________________________
firewall-wizards mailing list
firewall-wizards () nfr net
http://www.nfr.net/mailman/listinfo/firewall-wizards


Current thread: