LogAnalysis
[logs] Syslog and facilities Jun 06 2007 10:55AM
saudi sans (saudisans gmail com) (4 replies)
Re: [logs] Facility 101 (was: Syslog and facilities) Jun 18 2007 01:04PM
Chris Brenton (cbrenton chrisbrenton org) (1 replies)
[logs] Syslog and Windows Jun 22 2007 04:35AM
Bill Scherr IV (bschnzl cotse net) (5 replies)
RE: [logs] Syslog and Windows Jun 25 2007 06:54PM
Eric Fitzgerald (Eric Fitzgerald microsoft com) (2 replies)
RE: [logs] Syslog and Windows Jun 25 2007 08:02PM
Rainer Gerhards (rgerhards hq adiscon com) (1 replies)
RE: [logs] Syslog and Windows Jun 25 2007 08:43PM
Eric Fitzgerald (Eric Fitzgerald microsoft com) (1 replies)
RE: [logs] Syslog and Windows Jun 25 2007 09:10PM
Rainer Gerhards (rgerhards hq adiscon com) (1 replies)
RE: [logs] Syslog and Windows Jun 25 2007 09:55PM
Eric Fitzgerald (Eric Fitzgerald microsoft com)
Re: [logs] Syslog and Windows Jun 25 2007 07:59PM
Vincent Bernat (bernat luffy cx) (1 replies)
RE: [logs] Syslog and Windows Jun 26 2007 07:05PM
Eric Fitzgerald (Eric Fitzgerald microsoft com) (1 replies)
RE: [logs] Syslog and Windows Jun 26 2007 08:00PM
Rainer Gerhards (rgerhards hq adiscon com)
Re: [logs] Syslog and Windows Jun 22 2007 05:42AM
David Corlette (dcorlette novell com)
[logs] Re: Syslog and Windows Jun 22 2007 05:11AM
Chris Brenton (cbrenton chrisbrenton org) (1 replies)
[logs] Re: Syslog and Windows Jun 22 2007 10:23AM
Bill Scherr IV (bschnzl cotse net) (1 replies)
RE: [logs] Re: Syslog and Windows Jun 22 2007 06:27PM
Tina Bird (tbird precision-guesswork com) (3 replies)
RE: [logs] Re: Syslog and Windows Jun 23 2007 03:46PM
Chris Brenton (cbrenton chrisbrenton org)
On Fri, 2007-06-22 at 11:27 -0700, Tina Bird wrote:
>
> If I make take the substantial liberty of interpreting what Chris said, I
> think that what he meant is that he wouldn't use a Windows box as a central
> loghost, *not* that the logs produced by Windows systems themselves are
> problematic (aside from any native support for syslog).
>
> [If that's *not* what you meant, Chris, we may have to have it out with an
> arm-wrestling match or something.]

As always you are spot on but I'll still take you up on the arm
wrestling. ;-)

> It is, as far as I've seen, clear that syslog *server* implementations for
> UNIX variants offer far more features and robustness than the syslog servers
> for Windows, although I must confess to little experience with Windows
> syslog servers.

>From personal experience I would blame the IP stack. When it comes to
wire activity (IDS, firewall, etc.) for a given piece of hardware
Windows just comes up short when compared to Linux or UNIX variants.
Seeing as a logging server sees a lot of network I/O, I would guess the
problem lies here as well.

> >From the point of view of the logs themselves, I strongly defend my radical
> opinion that there are many ways in which the Windows Event Log is easier to
> use and more reliable than stock syslog:

Ya, as convoluted as the Event ID system has been over the years it
blows away anything on the Linux/UNIX side. Then again your talking a
single vendor with a complete monopoly so one would hope so. ;-)

> That being said, I'm sticking with syslog-ng for my central repository ;-)

+2!

Cheers,
Chris

_______________________________________________
LogAnalysis mailing list
LogAnalysis (at) loganalysis (dot) org [email concealed]
http://www.loganalysis.org/mailman/listinfo/loganalysis

[ reply ]
RE: [logs] Re: Syslog and Windows Jun 22 2007 08:41PM
Rainer Gerhards (rgerhards hq adiscon com)
Re: [logs] Re: Syslog and Windows Jun 22 2007 07:15PM
Gord Taylor (taylorgo gmail com) (1 replies)
RE: [logs] Re: Syslog and Windows Jun 22 2007 08:24PM
Rainer Gerhards (rgerhards hq adiscon com) (1 replies)
Re: [logs] Re: Syslog and Windows Jun 25 2007 02:24PM
Gord Taylor (taylorgo gmail com)
Re: [logs] Syslog and Windows Jun 22 2007 05:04AM
John Kinsella (jlk thrashyour com) (2 replies)
RE: [logs] Syslog and Windows Jun 22 2007 10:09AM
Rainer Gerhards (rgerhards hq adiscon com)
Re: [logs] Syslog and Windows Jun 22 2007 08:43AM
Russell Fulton (r fulton auckland ac nz) (1 replies)
Re: [logs] Syslog and Windows Jun 22 2007 03:12PM
John Kinsella (jlk thrashyour com)
Re: [logs] Syslog and Windows Jun 22 2007 04:49AM
Matt Jonkman (jonkman bleedingthreats net)
RE: [logs] Syslog and facilities Jun 06 2007 07:45PM
Rainer Gerhards (rgerhards hq adiscon com)
Re: [logs] Syslog and facilities Jun 06 2007 05:01PM
Marcus J. Ranum (mjr ranum com) (1 replies)
RE: [logs] Syslog and facilities Jun 06 2007 07:40PM
Rainer Gerhards (rgerhards hq adiscon com)
Re: [logs] Syslog and facilities Jun 06 2007 04:40PM
David Corlette (dcorlette novell com)


 

Privacy Statement
Copyright 2010, SecurityFocus