<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Logged</title>
	<atom:link href="http://www.syslog.org/logged/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.syslog.org/logged</link>
	<description>Event and Log Management</description>
	<lastBuildDate>Thu, 11 Mar 2010 02:53:28 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on Interesting ssh Brute Force Attack From Botnet by Using Trends In Logs To Define New Security Requirements For Internet Facing Hosts &#124; Logged</title>
		<link>http://www.syslog.org/logged/interesting-ssh-brute-force-attack-from-botnet/comment-page-1/#comment-61</link>
		<dc:creator>Using Trends In Logs To Define New Security Requirements For Internet Facing Hosts &#124; Logged</dc:creator>
		<pubDate>Thu, 11 Mar 2010 02:53:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.syslog.org/logged/?p=20#comment-61</guid>
		<description>[...] datacenter for running a number of sites, including this one.  I have written before about detecting brute force attacks in logs.   I have been watching the attacks continue in my logs, and have noticed a few [...]</description>
		<content:encoded><![CDATA[<p>[...] datacenter for running a number of sites, including this one.  I have written before about detecting brute force attacks in logs.   I have been watching the attacks continue in my logs, and have noticed a few [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Logging Windows Events To Syslog Using Snare by admin</title>
		<link>http://www.syslog.org/logged/logging-windows-events-to-syslog-using-snare/comment-page-1/#comment-21</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Tue, 23 Feb 2010 22:32:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.syslog.org/logged/?p=58#comment-21</guid>
		<description>No problem. Thanks for making Snare!</description>
		<content:encoded><![CDATA[<p>No problem. Thanks for making Snare!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Logging Windows Events To Syslog Using Snare by Leigh</title>
		<link>http://www.syslog.org/logged/logging-windows-events-to-syslog-using-snare/comment-page-1/#comment-20</link>
		<dc:creator>Leigh</dc:creator>
		<pubDate>Tue, 23 Feb 2010 21:33:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.syslog.org/logged/?p=58#comment-20</guid>
		<description>Thanks for the positive comments on Snare!

Glad you liked the USB features - it was a real chore to get right.

Regards,

Leigh (InterSect/Snare developer).</description>
		<content:encoded><![CDATA[<p>Thanks for the positive comments on Snare!</p>
<p>Glad you liked the USB features &#8211; it was a real chore to get right.</p>
<p>Regards,</p>
<p>Leigh (InterSect/Snare developer).</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Logging Windows Events To Syslog Using Snare by Running Syslog-NG on Windows &#124; Logged</title>
		<link>http://www.syslog.org/logged/logging-windows-events-to-syslog-using-snare/comment-page-1/#comment-16</link>
		<dc:creator>Running Syslog-NG on Windows &#124; Logged</dc:creator>
		<pubDate>Mon, 22 Feb 2010 16:24:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.syslog.org/logged/?p=58#comment-16</guid>
		<description>[...] This post describes running syslog-ng as a server on Windows.  In another post, we describe how to send Windows Event Logs to syslog. [...]</description>
		<content:encoded><![CDATA[<p>[...] This post describes running syslog-ng as a server on Windows.  In another post, we describe how to send Windows Event Logs to syslog. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Building A Program To Manage And Monitor Administrators by Defining Log Management and Log Monitoring Objectives &#124; Logged</title>
		<link>http://www.syslog.org/logged/program-to-manage-and-monitor-administrators/comment-page-1/#comment-10</link>
		<dc:creator>Defining Log Management and Log Monitoring Objectives &#124; Logged</dc:creator>
		<pubDate>Fri, 12 Feb 2010 23:19:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.syslog.org/logged/?p=111#comment-10</guid>
		<description>[...] This is one area of log management that many organizations unintentionally overlook, because the perceived risk is not very high, the administrators are unaware of the options, and more commonly, the view that monitoring the activity of administrators is futile because such monitoring could be bypassed by a skilled administrator.  In separate post, I describe a process to monitor the activities of administrators. [...]</description>
		<content:encoded><![CDATA[<p>[...] This is one area of log management that many organizations unintentionally overlook, because the perceived risk is not very high, the administrators are unaware of the options, and more commonly, the view that monitoring the activity of administrators is futile because such monitoring could be bypassed by a skilled administrator.  In separate post, I describe a process to monitor the activities of administrators. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Establishing a Hardened Syslog Log Server by Configuring SUDO for Effective Activity Monitoring Via Syslog &#124; Logged</title>
		<link>http://www.syslog.org/logged/establishing-a-hardened-syslog-log-server/comment-page-1/#comment-9</link>
		<dc:creator>Configuring SUDO for Effective Activity Monitoring Via Syslog &#124; Logged</dc:creator>
		<pubDate>Fri, 05 Feb 2010 22:26:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.syslog.org/logged/?p=78#comment-9</guid>
		<description>[...] cover his tracks by deleting logs.  This is best accomplished by streaming the logs to a hardened syslog server, where the administrator doesn&#8217;t have the ability to delete [...]</description>
		<content:encoded><![CDATA[<p>[...] cover his tracks by deleting logs.  This is best accomplished by streaming the logs to a hardened syslog server, where the administrator doesn&#8217;t have the ability to delete [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Establishing a Hardened Syslog Log Server by Building A Program To Manage And Monitor Administrators &#124; Logged</title>
		<link>http://www.syslog.org/logged/establishing-a-hardened-syslog-log-server/comment-page-1/#comment-8</link>
		<dc:creator>Building A Program To Manage And Monitor Administrators &#124; Logged</dc:creator>
		<pubDate>Sun, 24 Jan 2010 21:46:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.syslog.org/logged/?p=78#comment-8</guid>
		<description>[...] user monitoring program&#8221;, defined later.  Following the good practice of sending logs to a hardened log server for storage and processing will prevent determined administrators from covering his tracks by [...]</description>
		<content:encoded><![CDATA[<p>[...] user monitoring program&#8221;, defined later.  Following the good practice of sending logs to a hardened log server for storage and processing will prevent determined administrators from covering his tracks by [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Establishing a Hardened Syslog Log Server by Using Syslog Logs For Validation of Security Policy Compliance &#124; Logged</title>
		<link>http://www.syslog.org/logged/establishing-a-hardened-syslog-log-server/comment-page-1/#comment-7</link>
		<dc:creator>Using Syslog Logs For Validation of Security Policy Compliance &#124; Logged</dc:creator>
		<pubDate>Fri, 07 Aug 2009 21:49:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.syslog.org/logged/?p=78#comment-7</guid>
		<description>[...] ability to remove the log evidence of his presence, which is a very good reason to relay logs to a central syslog server.  It then becomes imperative that administrators with access to root accounts on systems do not [...]</description>
		<content:encoded><![CDATA[<p>[...] ability to remove the log evidence of his presence, which is a very good reason to relay logs to a central syslog server.  It then becomes imperative that administrators with access to root accounts on systems do not [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Logging Windows Events To Syslog Using Snare by Configuring syslog-ng to work with Snare &#124; Logged</title>
		<link>http://www.syslog.org/logged/logging-windows-events-to-syslog-using-snare/comment-page-1/#comment-6</link>
		<dc:creator>Configuring syslog-ng to work with Snare &#124; Logged</dc:creator>
		<pubDate>Wed, 13 May 2009 23:57:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.syslog.org/logged/?p=58#comment-6</guid>
		<description>[...] a previous post, we looked at installing Snare to log Windows events to a syslog server.  Here, we will configure syslog-ng to accept messages from Snare and implement a few simple [...]</description>
		<content:encoded><![CDATA[<p>[...] a previous post, we looked at installing Snare to log Windows events to a syslog server.  Here, we will configure syslog-ng to accept messages from Snare and implement a few simple [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Why Using A Log Management Service Might Be Right For You by Establishing a Hardened Syslog Log Server &#124; Logged</title>
		<link>http://www.syslog.org/logged/why-using-a-log-management-service-might-be-right-for-you/comment-page-1/#comment-5</link>
		<dc:creator>Establishing a Hardened Syslog Log Server &#124; Logged</dc:creator>
		<pubDate>Wed, 29 Apr 2009 22:58:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.syslog.org/logged/?p=34#comment-5</guid>
		<description>[...] The depth of protections that may need to be applied to a logs provides a good example of why a Log Management Service should be considered.   Tags: Centralized Log Server, Log Management Service Published by admin on [...]</description>
		<content:encoded><![CDATA[<p>[...] The depth of protections that may need to be applied to a logs provides a good example of why a Log Management Service should be considered.   Tags: Centralized Log Server, Log Management Service Published by admin on [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
