+ Logging, Syslog and Log Anaylsys Forums » Forums » Syslog & syslogd
|-+ 

syslog data mining

Username:
Password:
News:

Pages: 1 [2]
0 Members and 1 Guest are viewing this topic. Topic Tools  
Read February 02, 2005, 11:55:19 pm #15
mutex

syslog data mining

I hadn't ever heard of SEC, but it looks exactly like what is needed here.  A google shows the site as: http://kodu.neti.ee/~risto/sec/

I've added it to the web links as well.
Offline  
Read February 12, 2005, 04:58:07 pm #16
mutex

syslog data mining

Just reminder that there are many data mining tools listed (31 right now) in the we links at: http://www.syslog.org/Web_Links+index-req-viewlink-cid-4.phtml

Everyone has a slightly different take on how to do data mining & event correlation, so you really have to look for the tool(s) that are in line with what you want.
Offline  
Read October 16, 2008, 10:18:38 am #17
rgerhards

Re: syslog data mining

Probably the last follow-up for today. Somehow my subscriptions seem to have been out of order, else I would have subscribed earlier Wink

First, let me start with that MonitorWare is remote accessible, but you need to have registry access to the remote machine (the remote client uses that interface). It's reporting components are not as strong as is needed for enterprises, but this is changing Wink

As a free part of the MonitorWare line, we have begun to develop a GPLed, web based analysis, searching and graphing front-end for syslog and other network event data. It is called phpLogCon and plays nicely with the MonitorWare Agent and EventReporter products, which collect various data sources on Windows machines. For obvious reasons, it also works well with WinSyslog, a syslog server for Windows, and rsyslog, a GPLed syslogd replacement on *nix.

PhpLogCon can process data stored in a various databases (MySQL, Postgres, Oracle, ...) but also from plain text files - so you can simply point it to log files if you would like to have a quick look at them. Of course it is not perfect and it is currently being actively developed. Feedback on the tool (or the tool family) is appreciate. For a quick glimpse, you can check out the demo site at http://demo.phplogcon.org.
Offline  
Read October 24, 2008, 05:06:39 am #18
rgerhards

Re: syslog data mining

For those who would like to try the solution with minimal effort: I have just created a virtual syslog appliance with all the components pre-installed. More info and download under

http://www.syslogappliance.de
Offline  
Pages: 1 [2]
Jump to:  


Information Security News | Jerry Bell's blog | Enterprise IT | Tropical Fish Information | Tropical Fish Forums