[logs] medium to advanced logsurfer config examples?

From: download (Jim Prewett) (downloadat_private)
Date: Mon Sep 09 2002 - 15:30:02 PDT

  • Next message: Dan Barahona: "RE: [logs] centralized logging"

    All, 
    I'm looking for more info on setting up logsurfer.  I'm wondering if
    anyone has some example configs?
    
    I've seen emf's (very nice, thanks emf!) collection, but I'm looking for
    examples of why you might use a greater set of logsurfer's functionality.
    
    On a completely different, but related topic, I'm trying to set up
    logsurfer to (have an external program) count unsuccessful login attempts
    to a machine and would like to have the external program be as simple as
    possible.
    
    I want to be able to say "user foobar failed to log in 17 times".  The
    issue is that my log files have a line for every connection for every
    authentication method tried (but I want to count that as 1 attempt, not
    several).
    
    Many thanks,
    Jim
    
    
    -------------------------------------------------------------------------------
    \x83\xec\x0c\x31\xc0\x31\xd2\x68\x2f\x73\x68\x21\x68\x2f\x62\x69\x6e\x89\xe3
    \x88\x43\x07\x50\x50\x53\x53\xb0\x3b\xcd\x80\x89\xf6  Don't forget FreeBSD!
    -------------------------------------------------------------------------------
    
    _______________________________________________
    LogAnalysis mailing list
    LogAnalysisat_private
    http://lists.shmoo.com/mailman/listinfo/loganalysis
    



    This archive was generated by hypermail 2b30 : Mon Sep 09 2002 - 16:24:10 PDT