Security Basics mailing list archives

RE: Event log monitoring


From: "Kurt" <kurtbuff () spro net>
Date: Wed, 13 Oct 2004 15:41:30 -0700

http://ntsyslog.sourceforge.net or http://intersectalliance.com/snare -
will send your eventlogs to a syslog server in realtime

http://kiwisyslog.com - a very good syslog server for Windows, and if
you pay for it (it's very inexpensive for the impressive quality), it'll
even log to an ODBC DSN

http://mysql.com - A free SQL database server, with an ODBC interface,
both Windows and *nix.

Pretty much all you need.

| -----Original Message-----
| From: Stephane Auger [mailto:stephaneauger () pre2post com]
| Sent: Tuesday, October 12, 2004 13:26
| To: security-basics () securityfocus com
| Subject: Event log monitoring
| 
| 
| Hey everyone,
| 
|   I'm looking for a practical way to monitor event logs on multiple
| servers.  There are multiple subnets at multiple sites, and I have one
| main LAN to monitor everything.  Is there some kind of software/batch
| file that could be installed on the servers so that the events be sent
| on my monitoring lan (a little bit like SNMP sending to a listening
| server)?  Thanks!!
| 
| Stephane Auger, MCP

Current thread: