+ Logging, Syslog and Log Anaylsys Forums » Forums » Security
|-+ 

Using logs as part of security...

Username:
Password:
News:

Pages: [1]
0 Members and 2 Guests are viewing this topic. Topic Tools  
Read July 10, 2005, 06:37:10 pm #0
Anonymous

Using logs as part of security...

I believe many people are using log monitoring as part of system and network security, but how are people doing it?  what tools, and what information is sent, and how is it acted on?  We currently don't do any proactive log analysis.
 
Read July 29, 2005, 09:51:40 am #1
Henke

Using logs as part of security...

Hi!

We have a central syslogserver which is running FreeBSD with syslog-ng and phpsyslogng.

We save logs to both mysql (For easy searching with phpsyslogng) and to file.
We rotate logs once a month and save them for a year. We do not monitor the logs all day long, but search for critical errors and so once a week maybe. And of course when the boss has some supcicions, or we just want too look at something like "who locked that account out!?"

We use NT-syslog on our windows servers, and standard syslogd on our unixes.

When the day comes that we have any problem with whatever, we will sure be glad to have the syslogs together with IDS/NIDS, firewall logs and so on. It has only happened once though, with an angry ex. employee.

Logging is an important part of security.

For system failure and things like harddrivecrashes, we have other tools.

/Henrik
 
Read July 29, 2005, 09:59:18 am #2
mutex

Using logs as part of security...

That makes a lot of sense.  I do much the same thing, but I run devialog against the logs to provide more of a real-time alert when something out of the ordinary happens.  It's working pretty well now.
Offline  
Pages: [1]
Jump to:  

Information Security News | Jerry Bell's blog | Enterprise IT | Tropical Fish Information | Tropical Fish Forums