Security Basics mailing list archives

RE: FW/IPS log correlation software


From: "Brandon Louder" <Brandon.Louder () mckennan org>
Date: Thu, 3 Apr 2008 11:27:01 -0500

Have you looked at MARS? It does event correlation quite well with a GUI frontend. 

http://www.cisco.com/en/US/products/ps6241/index.html


-----Original Message-----
From: listbounce () securityfocus com [mailto:listbounce () securityfocus com] On Behalf Of Raimar Melchior
Sent: Thursday, April 03, 2008 8:39 AM
To: security-basics () securityfocus com
Subject: FW/IPS log correlation software

Hello list,

we want a central log station where logs from firewalls, ips and other 
security devices are sent to. All of our components support the syslog 
protocol.
The challange is to filter and correlate this huge amount of logs. We 
also want to create filtering and reports (graphical). The server should 
have a graphical frontend (gui).
We tried the kiwi syslog server but it doesn't meet our requirements. 
Any good enterprise software out there ?
Any suggestions would be very appreciated.

Many Thanks,
Raimar

Security Consultant

CROCODIAL IT Security GmbH

Niederlassung Köln
Von-der-Wettern-Str. 25
51149 Köln

office: +492203-69923-16
mobile: +49170-2265680
eMail: rm () crocodial de
http://www.crocodial.de/


Sitz der Gesellschaft: Hamburg
Eingetragen: Amtsgericht Hamburg Nr. HRB 83456
Geschäftsführung: Wolfgang Dierke, Helmut Hansen, Lutz Klöber

----------------------------------------------------------------------
CROCODIAL SecurityDays 2008:
----------------------------------------------------------------------
  Berlin:      16.04.2008          Hamburg:     22.02.2008
               26.09.2008                       05.09.2008
  Bremen:      04.04.2008          Hannover:    18.04.2008
               12.09.2008                       19.09.2008
  Dortmund:    23.10.2008          Köln:        05.06.2008
  Düsseldorf:  10.04.2008



-----------------------------------------
Confidentiality Notice: This e-mail message, including any
attachments, is for the sole use of the intended recipient(s) and
may contain confidential and privileged information. Any
unauthorized review, use, disclosure, or distribution is
prohibited. If you are not the intended recipient, please contact
the sender by reply e-mail and destroy all copies of the original
message.


Current thread: