Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - Syslog analyzer

 
Thread Tools Search this Thread
Old 05-14-2004, 06:12 PM   #1
Default Syslog analyzer


Hi to all
I'm looking for a I.D.S. or a configurable log analyzer who can acquire
syslog from a firewall (actually I'm using a netgear's FR114P).
I've tried with kiwi syslog analyzer, but my goal is not only to collect
log, but possibly to signal when a strange activity is reported (a ping, a
simple, isolated portscan or an attempt to establish a connection can be
considered a "normal" noise in internet, 10 portscan or something other
repetitive can be considered a "real" attack).

Now with kiwi syslog a complete portscan realize 65000 logs... really not
friendly. The optimum can be a pop-up who tells me there is an attack from
an IP, or something similar.

Can you help me?
Thank you very Much
Michele


ACM
  Reply With Quote
Old 05-15-2004, 07:57 PM   #2
Chuck
 
Posts: n/a
Default Re: Syslog analyzer
On Fri, 14 May 2004 19:12:21 +0200, ACM <michele-no-spam-@acmsolution.com> wrote:

>Hi to all
>I'm looking for a I.D.S. or a configurable log analyzer who can acquire
>syslog from a firewall (actually I'm using a netgear's FR114P).
>I've tried with kiwi syslog analyzer, but my goal is not only to collect
>log, but possibly to signal when a strange activity is reported (a ping, a
>simple, isolated portscan or an attempt to establish a connection can be
>considered a "normal" noise in internet, 10 portscan or something other
>repetitive can be considered a "real" attack).
>
>Now with kiwi syslog a complete portscan realize 65000 logs... really not
>friendly. The optimum can be a pop-up who tells me there is an attack from
>an IP, or something similar.
>
>Can you help me?
>Thank you very Much
> Michele


Michele,

Give Link Logger a try. It comes with a 14 day trial period.
http://www.linklogger.com/

Cheers,

Chuck
I hate spam - Please get rid of the spam if you want to email me!!
Trusted Computing? Right! http://www.againsttcpa.com/


Chuck
  Reply With Quote
Old 05-17-2004, 08:02 AM   #3
ACM
 
Posts: n/a
Default Re: Syslog analyzer
In data Sat, 15 May 2004 18:57:16 GMT, Chuck ha scritto:

> On Fri, 14 May 2004 19:12:21 +0200, ACM <michele-no-spam-@acmsolution.com> wrote:
>
>>Hi to all
>>I'm looking for a I.D.S. or a configurable log analyzer who can acquire
>>syslog from a firewall (actually I'm using a netgear's FR114P).
>>I've tried with kiwi syslog analyzer, but my goal is not only to collect
>>log, but possibly to signal when a strange activity is reported (a ping, a
>>simple, isolated portscan or an attempt to establish a connection can be
>>considered a "normal" noise in internet, 10 portscan or something other
>>repetitive can be considered a "real" attack).
>>
>>Now with kiwi syslog a complete portscan realize 65000 logs... really not
>>friendly. The optimum can be a pop-up who tells me there is an attack from
>>an IP, or something similar.
>>
>>Can you help me?
>>Thank you very Much
>> Michele

>
> Michele,
>
> Give Link Logger a try. It comes with a 14 day trial period.
> http://www.linklogger.com/
>
> Cheers,
>
> Chuck
> I hate spam - Please get rid of the spam if you want to email me!!
> Trusted Computing? Right! http://www.againsttcpa.com/


Thank you, but I'm using yet linklogger. It's a good program but it has
some limitations: first I can't create a remote control of log (i can only
send e-mail notification).
I'm looking for a configurable program which can receive syslog string and
analyze them from a remote site, so linklogger isn't the right solution.
Thank you
Michele


ACM
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46