Logging, Syslog and Log Anaylsys Forums
July 30, 2010, 09:37:44 pm *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News:
   Home   WIKI BLOG Help Search Recent Topics GoogleTagged Login Register  
Pages: [1]
  Print  
Author Topic: Most important log of linux and cisco  (Read 666 times)
capricorn80
Newbie
*
Offline Offline

Posts: 28


View Profile
« on: February 19, 2010, 06:51:26 pm »


 Hi!

  what are the most important log from security point of view in linux and cisco ?

Regards,
Logged
Admin
Administrator
Newbie
*****
Offline Offline

Posts: 146


View Profile WWW
« Reply #1 on: February 19, 2010, 08:38:02 pm »

For linux, out of the box the most important files are going to be /var/log/auth.log and /var/log/messages. 

For cisco, it really depends on how the device is configured.
Logged
capricorn80
Newbie
*
Offline Offline

Posts: 28


View Profile
« Reply #2 on: February 20, 2010, 07:09:42 am »


 Can you give me some idea about CISCO . I got 4500 and 6500 series switches.

Thanks
Logged
Admin
Administrator
Newbie
*****
Offline Offline

Posts: 146


View Profile WWW
« Reply #3 on: February 20, 2010, 03:12:14 pm »

Are you running catos or ios on those switches?  What is the current logging config?
Logged
capricorn80
Newbie
*
Offline Offline

Posts: 28


View Profile
« Reply #4 on: February 22, 2010, 02:57:25 am »

its IOS
i have setup local6 and logging syslog-ng server ip addess.
Logged
Admin
Administrator
Newbie
*****
Offline Offline

Posts: 146


View Profile WWW
« Reply #5 on: February 23, 2010, 08:13:10 am »

All of the syslog messages from the IOS switch are going to come through on local6.  It will be up to syslog-ng to separate the messages based on the priority.  The priorities that would be important to look at are:
warn, error, critical, alert and emergency. 

You can accomplish this with a filter like this:
Code:
filter f_importantIOSstuff {level(warn...emerg); };
Logged
Pages: [1]
  Print  

 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC | Sitemap Valid XHTML 1.0! Valid CSS!