|
LogAnalysis
[logs] Syslog and facilities Jun 06 2007 10:55AM saudi sans (saudisans gmail com) (4 replies) Re: [logs] Facility 101 (was: Syslog and facilities) Jun 18 2007 01:04PM Chris Brenton (cbrenton chrisbrenton org) (1 replies) [logs] Syslog and Windows Jun 22 2007 04:35AM Bill Scherr IV (bschnzl cotse net) (5 replies) RE: [logs] Syslog and Windows Jun 25 2007 06:54PM Eric Fitzgerald (Eric Fitzgerald microsoft com) (2 replies) RE: [logs] Syslog and Windows Jun 25 2007 08:02PM Rainer Gerhards (rgerhards hq adiscon com) (1 replies) RE: [logs] Syslog and Windows Jun 25 2007 08:43PM Eric Fitzgerald (Eric Fitzgerald microsoft com) (1 replies) RE: [logs] Syslog and Windows Jun 25 2007 09:10PM Rainer Gerhards (rgerhards hq adiscon com) (1 replies) Re: [logs] Syslog and Windows Jun 25 2007 07:59PM Vincent Bernat (bernat luffy cx) (1 replies) RE: [logs] Syslog and Windows Jun 26 2007 07:05PM Eric Fitzgerald (Eric Fitzgerald microsoft com) (1 replies) [logs] Re: Syslog and Windows Jun 22 2007 05:11AM Chris Brenton (cbrenton chrisbrenton org) (1 replies) [logs] Re: Syslog and Windows Jun 22 2007 10:23AM Bill Scherr IV (bschnzl cotse net) (1 replies) RE: [logs] Re: Syslog and Windows Jun 22 2007 06:27PM Tina Bird (tbird precision-guesswork com) (3 replies) Re: [logs] Re: Syslog and Windows Jun 22 2007 07:15PM Gord Taylor (taylorgo gmail com) (1 replies) RE: [logs] Re: Syslog and Windows Jun 22 2007 08:24PM Rainer Gerhards (rgerhards hq adiscon com) (1 replies) Re: [logs] Syslog and Windows Jun 22 2007 05:04AM John Kinsella (jlk thrashyour com) (2 replies) Re: [logs] Syslog and Windows Jun 22 2007 08:43AM Russell Fulton (r fulton auckland ac nz) (1 replies) |
|
Privacy Statement |
>
> If I make take the substantial liberty of interpreting what Chris said, I
> think that what he meant is that he wouldn't use a Windows box as a central
> loghost, *not* that the logs produced by Windows systems themselves are
> problematic (aside from any native support for syslog).
>
> [If that's *not* what you meant, Chris, we may have to have it out with an
> arm-wrestling match or something.]
As always you are spot on but I'll still take you up on the arm
wrestling. ;-)
> It is, as far as I've seen, clear that syslog *server* implementations for
> UNIX variants offer far more features and robustness than the syslog servers
> for Windows, although I must confess to little experience with Windows
> syslog servers.
>From personal experience I would blame the IP stack. When it comes to
wire activity (IDS, firewall, etc.) for a given piece of hardware
Windows just comes up short when compared to Linux or UNIX variants.
Seeing as a logging server sees a lot of network I/O, I would guess the
problem lies here as well.
> >From the point of view of the logs themselves, I strongly defend my radical
> opinion that there are many ways in which the Windows Event Log is easier to
> use and more reliable than stock syslog:
Ya, as convoluted as the Event ID system has been over the years it
blows away anything on the Linux/UNIX side. Then again your talking a
single vendor with a complete monopoly so one would hope so. ;-)
> That being said, I'm sticking with syslog-ng for my central repository ;-)
+2!
Cheers,
Chris
_______________________________________________
LogAnalysis mailing list
LogAnalysis (at) loganalysis (dot) org [email concealed]
http://www.loganalysis.org/mailman/listinfo/loganalysis
[ reply ]