Security Incidents mailing list archives

Re: traffic logging


From: smcclell () VORTEXDATA COM (Scott McClelland)
Date: Mon, 1 May 2000 16:55:12 -0700


I've been seeing a lot of odd traffic on several of my
machines and I was
wondering what you folks suggest for logging traffic on a
single machine.
Several of the machines are Linux boxes, and I'd like the
ability to log in
depth.  Things I'd like to capture would include things like
stealth scans
and odd packets.

Any suggestions?

Not so much for traffic, but I use logcheck for any anomolies in the log
files, and PortSentry to detect and react to port scans.  They can both be
found here:
http://www.psionic.com/

/*---------------------------------------------------------
Scott McClelland, CNA
Network Administrator
Vortex Data Systems
(619) 497-6400 x229
-----------------------------------------------------------*/


Current thread: