LogAnalysis
[logs] syslog config file format poll Sep 06 2007 03:42PM
Rainer Gerhards (rgerhards hq adiscon com) (2 replies)
Re: [logs] syslog config file format poll Sep 07 2007 07:00PM
Andreux Fort ($B$"$s$I$j$e!<(B) (afort choqolat org) (1 replies)
Re: [logs] syslog config file format poll Sep 07 2007 10:19PM
Anton Chuvakin (anton chuvakin org)
Re: [logs] syslog config file format poll Sep 06 2007 06:31PM
Marcin Antkiewicz (loganalysis kajtek org) (1 replies)
Re: [logs] syslog config file format poll Sep 06 2007 09:13PM
Marcus J. Ranum (mjr ranum com) (2 replies)
Re: [logs] syslog config file format poll Sep 07 2007 11:56AM
Greg Dotoli (gldotoli yahoo com)
Re: [logs] syslog config file format poll Sep 07 2007 10:30AM
Mordechai T. Abzug (morty frakir org) (2 replies)
RE: [logs] syslog config file format poll Sep 10 2007 09:16AM
Rainer Gerhards (rgerhards hq adiscon com) (1 replies)
Re: [logs] syslog config file format poll Sep 11 2007 05:19PM
Bennett Todd (bet rahul net)
Re: [logs] syslog config file format poll Sep 07 2007 05:52PM
David Corlette (dcorlette novell com) (1 replies)
Re: [logs] syslog config file format poll Sep 11 2007 12:56PM
Balazs Scheidler (bazsi balabit hu) (2 replies)
Re: [logs] syslog config file format poll Sep 13 2007 03:04AM
David Corlette (dcorlette novell com) (1 replies)
Re: [logs] syslog config file format poll Sep 13 2007 01:43PM
Balazs Scheidler (bazsi balabit hu) (1 replies)
RE: [logs] syslog config file format poll Sep 14 2007 06:12AM
Rainer Gerhards (rgerhards hq adiscon com)
[logs] Syslog - monitoring the bigger picture Sep 12 2007 07:33PM
Mervin Pearce [SACS] (mervin sacs co za) (1 replies)
Re: [logs] Syslog - monitoring the bigger picture Sep 13 2007 06:10PM
Anton Chuvakin (anton chuvakin org) (1 replies)
RE: [logs] Syslog - monitoring the bigger picture Sep 13 2007 11:11PM
Tina Bird (tbird precision-guesswork com) (1 replies)

> Just curious, what is wrong with all other past logging projects, that
> seek to accomplish just about the same?

now *there's* a question for the ages.

what i usually tell my students:

"some junior sys admin who just took a perl/C/lisp/whatever class is tasked
with centralizing and monitoring system logs at her job. after getting all
the data centralized, she begins to look at the data and to try to
understand what's important and what isn't.

once she starts figuring out what she needs in terms of reports and alerts,
she hits the net, because *surely* this is a solved problem. she gets a lot
of google hits for swatch, so she starts there -- but it doesn't handle
thresholding traffic, which is critical for the firewall, and the job of
coming up with all the right keywords is less than exciting. so she asks
around a bit, and someone mentions logsurfer, cos it lets you deal with
multi-line messages and context, so she can get the contexting she needs.

but logsurfer is pretty complicated for what she needs, and she can't tell
whether it's still being maintained, or, for that matter, if it *matters*
whether or not it's still being maintained. and her manager keeps asking for
progress reports.

so finally she throws together a little script/program/spell that does
*exactly* what her organization needs. it may be tweaked for a particular
vendor's products, or the specific reporting requirements of her industry,
or whatever. but it does the trick for her and her manager is happy and she
can finally get onto something more interesting.

then she posts it on her website, and (with any luck) pretty much forgets
about it for the rest of her life."

...lather, rinse, repeat.

let me pre-emptively apologize to all list members who have contributed to
the log analysis and management tools that are out there. it's clear that
many of the folks involved in these projects take a much more big-picture
view than i've painted here, and i don't mean to smear them with the same
brush.

but wow, after 5 years of trying to maintain an up-to-date list of log
parsing and analysis tools -- which included attempting to figure out how
they differed from each other -- this is the only explanation i've been able
to come up with.

cheers -- tbird
_______________________________________________
LogAnalysis mailing list
LogAnalysis (at) loganalysis (dot) org [email concealed]
http://www.loganalysis.org/mailman/listinfo/loganalysis

[ reply ]
Re: [logs] Syslog - monitoring the bigger picture Sep 14 2007 06:25PM
Anton Chuvakin (anton chuvakin org) (1 replies)
RE: [logs] Syslog - monitoring the bigger picture Sep 14 2007 06:52PM
Tina Bird (tbird precision-guesswork com) (1 replies)
RE: [logs] Syslog - monitoring the bigger picture Sep 14 2007 08:10PM
David Corlette (dcorlette novell com) (2 replies)
Re: [logs] Syslog - monitoring the bigger picture Sep 15 2007 07:51AM
Tom Le (dottom gmail com)
RE: [logs] Syslog - monitoring the bigger picture Sep 14 2007 09:29PM
Tina Bird (tbird precision-guesswork com) (1 replies)
RE: [logs] Syslog - monitoring the bigger picture Sep 15 2007 03:38AM
David Corlette (dcorlette novell com)


 

Privacy Statement
Copyright 2010, SecurityFocus