Date: Mon, 20 Feb 2006 17:00:44 +0000 From: Ashley Moran <work@ashleymoran.me.uk> To: freebsd-questions@freebsd.org Subject: Re: Log analysis server suggestions? [long] Message-ID: <200602201700.44440.work@ashleymoran.me.uk> In-Reply-To: <43F49A81.4090203@mac.com> References: <200602161418.32982.ashley.moran@codeweavers.net> <43F4951E.5090203@wmptl.com> <43F49A81.4090203@mac.com>
next in thread | previous in thread | raw e-mail | index | archive | help
On Thursday 16 February 2006 15:30, Chuck Swiger wrote: > I'm not sure who the original poster was, but whoever is interested in this > topic might benefit by reading a thread from the firewall-wizards mailing > list: <snip> Cheers that was very useful- I've put it into our company Wiki so it can be ignored by everyone :) I like the 3-stage processing: > Simply design your analysis as an always 3-stage process consisting of: > - weeding out and counting instances of uninteresting events > - selecting, parsing sub-fields of, and processing interesting events > - retaining events that fell through the first two steps as "unusual" That solves the problem of missing logs that you didn't anticipate, although it adds a lot to the initial server configuration. Ashley
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200602201700.44440.work>