|
Colapse all |
Post message
[logs] Problem with Cisco message documentation 2007-11-27 Tina Bird (tbird precision-guesswork com) (1 replies) Hi all -- I'm not clear on where to send this question within Cisco's normal support channels, so I'll take advantage of the various Cisco employees and VARs on this list to try to answer my question (or give me an idea of where to direct it). I am making a list of PIX/ASA log messages related to [ more ] [ reply ] [logs] Administrivia: spam reduction measures 2007-11-22 Tina Bird (tbird precision-guesswork com) Hi all -- Before I migrated the list to its new server, I used the "must be a member to post" requirement to keep the amount of spam at a minimum. Since the move in February, we've had that *disabled*, to help people who didn't realize that the hosting server had changed, as well as to be sure we h [ more ] [ reply ] [logs] UDP/TCP load balancer recommendations 2007-11-20 Steve Bernacki (loganalysis f copacetic net) (3 replies) My organization is about to embark on a project to fortify our log capture and analysis infrastructure. One item that I've identified as being necessary is a load balancer to spread the incoming message stream (primarily syslog/udp) across our back-end syslog-ng receivers. In the past we have [ more ] [ reply ] Re: [logs] UDP/TCP load balancer recommendations 2007-11-20 Marcin Antkiewicz (loganalysis kajtek org) [logs] New LinkedIn Group created: Log Analysis Professionals 2007-11-19 Andrew Hay (andrewsmhay gmail com) Hello All, I know that a few of us are already on LinkedIn so I thought I'd share a newly created Log Analysis Professionals group with everyone. If you deal with events and logs on a day to day basis (in any capacity) then this is the group for you :) Please use the following link to submit your [ more ] [ reply ] [logs] Log Monitoring and Device Management 2007-11-19 saudi sans (saudisans gmail com) (1 replies) Hi, We have currently outsourced security device[firewall, IDS and VPN] log monitoring to a service provider. Now we need to outsource the management of these devices like changing firewall rulebase, updating firewall patches, fine tuning IDS signatures etc. Is it advisable to give this also to [ more ] [ reply ] [logs] CanSecWest 2008 CFP (deadline Nov 30,conf Mar 26-28) and PacSec Dojo's 2007-11-09 Dragos Ruiu (dr kyx net) (1 replies) I'd like to congratulate Adam Laurie for winning the second Powerbook from the Pwn_to_Own contest as the prize for the best speaker rated by the audience for his presentation on RFID at CanSecWest 2007. We will have a similar prize for the best speaker at CanSecWest 2008, prize TBD (but we promise i [ more ] [ reply ] [logs] How to log - commands and file access 2007-11-09 david bigot devoteam com (6 replies) RE: [logs] How to log - commands and file access 2007-11-12 Kurt Buff (KBuff zetron com) (1 replies) RE: [logs] How to log - commands and file access 2007-11-13 David Corlette (dcorlette novell com) (1 replies) Re: [logs] How to log - commands and file access 2007-11-12 Mike Blomgren (mike blomgren tornado se) (1 replies) Re: [logs] How to log - commands and file access 2007-11-09 Anton Chuvakin (anton chuvakin org) (2 replies) Re: [logs] How to log - commands and file access 2007-11-10 James Turnbull (james lovedthanlost net) FW: [logs] "Missing" Microsoft Event Log events 2007-11-05 Tina Bird (tbird precision-guesswork com) > The Events and Errors message center is not updated regularly > (it's interrupt-driven, not polling). It is also possible > that the Certificate Server events were never delivered to > EEMC; in the source code they are in a separate file than the > other security event log events and might h [ more ] [ reply ] [logs] OSSIM and/or OSSEC-HIDS 2007-10-31 Brian Bemis (brian_bemis hotmail com) I've been interested in expanding our log analysis capabilities and have come across a number of promising open-source projects out there, but I'm a little confused as to what each one does and doesn't do. The 2 most popular seem to be OSSIM and OSSEC-HIDS (I've also run across OpenSIMS as well). I [ more ] [ reply ] [logs] dns server as a db lookup 2007-10-31 anthony spina (aspina gmail com) Check out my post here : http://ipintel.blogspot.com/2007/10/2-perl-modules-and-15-database.html In summary, In an effort to fill the void of all the failed reverse lookups in my log analysis tool, I wrote a simple perl script that implements a nameserver, allowing me to pass custom results, which [ more ] [ reply ] [logs] In Memoriam: Jun-ichiro Hagino 2007-10-30 Dragos Ruiu (dr kyx net) With great sadness, I regret to inform you that Itojun will not be presenting his great knowledge of IPv6 at PacSec. I have been informed by several sources that he passed away yesterday. Funeral services will be held on Nov 7th at Rinkai-Saijo in Tokyo. There aren't many details of his passing, [ more ] [ reply ] |
|
Privacy Statement |
regarding syslog load balancing.
I'm currently researching how to best implement a high-peformance, high
volume syslog aggregation. In our current environment, we have many
devices logging to a small set of "front end" syslog agg
[ more ] [ reply ]