Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 20 Feb 2006 17:00:44 +0000
From:      Ashley Moran <work@ashleymoran.me.uk>
To:        freebsd-questions@freebsd.org
Subject:   Re: Log analysis server suggestions? [long]
Message-ID:  <200602201700.44440.work@ashleymoran.me.uk>
In-Reply-To: <43F49A81.4090203@mac.com>
References:  <200602161418.32982.ashley.moran@codeweavers.net> <43F4951E.5090203@wmptl.com> <43F49A81.4090203@mac.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On Thursday 16 February 2006 15:30, Chuck Swiger wrote:
> I'm not sure who the original poster was, but whoever is interested in this
> topic might benefit by reading a thread from the firewall-wizards mailing
> list:

<snip>

Cheers that was very useful- I've put it into our company Wiki so it can be 
ignored by everyone :)

I like the 3-stage processing:
> Simply design your analysis as an always 3-stage process consisting of:
> - weeding out and counting instances of uninteresting events
> - selecting, parsing sub-fields of, and processing interesting events
> - retaining events that fell through the first two steps as "unusual"

That solves the problem of missing logs that you didn't anticipate, although 
it adds a lot to the initial server configuration.

Ashley



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200602201700.44440.work>