Re: [logs] Logging - descriptive vs normative

From: Raistlin (raistlinat_private)
Date: Thu Aug 22 2002 - 11:17:30 PDT

  • Next message: Chris Adams: "Re: Re[2]: [logs] Logging: World Domination"

    > I
    > recognize the need for categorization/classification (descriptive);
    
    I am currently working out with some detail an intrusion detection system
    (but it should be quite adapt to log parsing too) based on neural network
    classifiers. I dismissed the possibility of analyzing system logs exactly
    for the reasons being debated here.
    
    A well defined token structure for log files would make them as easily
    machine-readable as apache weblogs or TCPdump logs are.
    
    XML is obviously an interesting choice, IMVHO, but really, any standard
    format would do.
    
    _______________________________________________
    LogAnalysis mailing list
    LogAnalysisat_private
    https://lists.shmoo.com/mailman/listinfo/loganalysis
    



    This archive was generated by hypermail 2b30 : Thu Aug 22 2002 - 11:35:38 PDT