Re: [loganalysis] fwlogwatch feedback

From: Andreas Östling (andreasoat_private)
Date: Fri Aug 24 2001 - 23:32:44 PDT

  • Next message: Mordechai T. Abzug: "Re: [loganalysis] stopping/starting swatchn"

    On Fri, 24 Aug 2001, n gold wrote:
    
    > I have been playing around with fwlogwatch
    > (cert.uni-stuttgart.de/projects/fwlogwatch) and wondered if anyone has
    > had experience with it.  In particular, I am curious about how it might
    > perform with log files on a log host other than the PIX logs, Cisco IOS
    > logs, and so on for which the tool was created.  Any one done any
    > "tricks" with the tool and care to share?
    
    I like it but I don't really do any special tricks with it.
    Every 30 minutes I generate two web pages containing logs from the last
    24 hours - one with Cisco IOS logs and another that collects firewall logs
    from diverse hosts (not the "real" firewalls) by some cat 'n grep on the
    syslog server. Those logs are mostly from IP filter, and also a few
    ipchains and iptables. It works very well with all those formats and is
    a very nice complement to normal log reading.
    
    Regards,
    Andreas Östling
    
    
    ---------------------------------------------------------------------
    To unsubscribe, e-mail: loganalysis-unsubscribeat_private
    For additional commands, e-mail: loganalysis-helpat_private
    



    This archive was generated by hypermail 2b30 : Sun Aug 26 2001 - 07:41:10 PDT