Logging, Syslog and Log Anaylsys Forums
September 08, 2010, 08:49:18 am
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
:
Home
WIKI
BLOG
Help
Search
Recent Topics
GoogleTagged
Login
Register
Logging, Syslog and Log Anaylsys Forums
>
Forums
>
Security Event Management
>
Using logs as part of security...
Pages: [
1
]
« previous
next »
Print
Author
Topic: Using logs as part of security... (Read 3743 times)
Anonymous
Guest
Using logs as part of security...
«
on:
July 10, 2005, 06:37:10 pm »
I believe many people are using log monitoring as part of system and network security, but how are people doing it? what tools, and what information is sent, and how is it acted on? We currently don't do any proactive log analysis.
Logged
Henke
Guest
Using logs as part of security...
«
Reply #1 on:
July 29, 2005, 09:51:40 am »
Hi!
We have a central syslogserver which is running FreeBSD with syslog-ng and phpsyslogng.
We save logs to both mysql (For easy searching with phpsyslogng) and to file.
We rotate logs once a month and save them for a year. We do not monitor the logs all day long, but search for critical errors and so once a week maybe. And of course when the boss has some supcicions, or we just want too look at something like "who locked that account out!?"
We use NT-syslog on our windows servers, and standard syslogd on our unixes.
When the day comes that we have any problem with whatever, we will sure be glad to have the syslogs together with IDS/NIDS, firewall logs and so on. It has only happened once though, with an angry ex. employee.
Logging is an important part of security.
For system failure and things like harddrivecrashes, we have other tools.
/Henrik
Logged
mutex
Administrator
Newbie
Offline
Posts: 901
Using logs as part of security...
«
Reply #2 on:
July 29, 2005, 09:59:18 am »
That makes a lot of sense. I do much the same thing, but I run devialog against the logs to provide more of a real-time alert when something out of the ordinary happens. It's working pretty well now.
Logged
Pages: [
1
]
Print
GoogleTagged:
syslog org security
log
phpsyslogng freebsd
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Forums
-----------------------------
=> Syslog & syslogd
=> syslog-ng
=> Log Data and Analysis
=> Windows Event Log
=> Web Server Logs
=> Security Event Management
=> General Discussion
===> Red Light District
Loading...