Security Basics mailing list archives

Logs from Firewall NetScreen


From: nbniel () gmail com
Date: Mon, 5 Sep 2011 21:03:47 GMT

Hello,
I'm wonder if someone knows what are the options of logs that should be activated in the syslogs of firewall netscreen, 
in my case, we have the next log settings:
- Emergency    -> Activated
- Alert        -> Activated
- Critical     -> Activated
- Error        -> Activated
- Warning      -> Deactivated
- Notification -> Deactivated
- Information  -> Deactivated
- Debugging    -> Deactivated

But i'do not know if they are the best practices, i would think to keep activated just Emergency, Alert, Critical and 
Notification but i'm not sure; or the other option is to activate all...
The problem with the last is that there's too much information that my SIEM received and don't know if every event is 
important to monitor...
I hope someone could help me...

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how 
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Current thread: