Firewall Wizards mailing list archives
RE: WORM file system for logging
From: "Marcus J. Ranum" <mjr () nfr net>
Date: Wed, 05 Aug 1998 10:31:36 -0400
As attractive as WORM drives appear, they are a pain in the butt to use - our group had one at a distant job, and it never got set up at all because it was such a pain to align and configure. :( Add to that the fact that the filesystems tend to overwrite (like a multimode CDROM) and it doesn't work very well. I guess the question is one of requirements. If what you need is a tamper proof storage medium, I'd suggest a whacked-on PC with a cut transmit lead that sucks syslog packets straight off the wire, then bundles the data and moves it to a CD-R every so often. (You could build this easily with and NFR, all except the CD-R integration which is an exercise for the reader) You've got a problem any time that you want to pull data off a network and commit it to a permanent log. The logging agent or the logger could be accidentally or deliberately DOS attacked. That might result in data loss. Can't trust the endpoints to queue up data because it might be corrupted, etc, etc. Perhaps if you can tell us your requirements, we can suggest something that'd match more closely. mjr. -- Marcus J. Ranum, CEO, Network Flight Recorder, Inc. work - http://www.nfr.net home - http://www.clark.net/pub/mjr
Current thread:
- WORM file system for logging Andreas Siegert (Aug 03)
- Re: WORM file system for logging Marcus J. Ranum (Aug 03)
- Re: WORM file system for logging Carlos Bachmaier (Aug 03)
- Re: WORM file system for logging Rick Smith (Aug 03)
- RE: WORM file system for logging Andrew J. Luca (Aug 05)
- RE: WORM file system for logging Marcus J. Ranum (Aug 05)
- Re: WORM file system for logging Andreas Siegert (Aug 06)
- Re: WORM file system for logging Marcus J. Ranum (Aug 06)
- Re: WORM file system for logging Adam Shostack (Aug 06)
- Re: WORM file system for logging Joseph S. D. Yao (Aug 06)
- Re: WORM file system for logging Bobo Rajec (Aug 07)
- Re: WORM file system for logging Doug Hughes (Aug 07)
- RE: WORM file system for logging Marcus J. Ranum (Aug 05)
- <Possible follow-ups>
- RE: WORM file system for logging Resino, Robert G. (Aug 03)
- Re: WORM file system for logging Andreas Siegert (Aug 04)
- Re: WORM file system for logging Paul McNabb (Aug 06)