Re: [logs] absence of evidence...

From: Klaus Moeller (moellerat_private)
Date: Mon Dec 16 2002 - 09:24:54 PST

  • Next message: Rodney Thayer: "Re: [logs] log data in court (was administrivia)"

    -----BEGIN PGP SIGNED MESSAGE-----
    
    On Monday 16 December 2002 14:47, you wrote:
    > 2002-12-16-00:32:38 Tina Bird:
    
    > > anyone out there have a tool that can parse syslog data (or
    > > anything text based, i guess) and send an alert if a particular
    > > message does >not< show up?
    
    Yes, it can be done with logsurfer. Think of sessions logged by ftpd or 
    sshd, for example. Use the stop-regexp or not-match-regexp for the line 
    that has not to show up.
    
    Regards,
    		Klaus Moeller, DFN-CERT
    
    - -- 
    Klaus Moeller          |                      mailto:moellerat_private
    DFN-CERT GmbH          |            http://www.cert.dfn.de/team/moeller/
    Heidenkampsweg 41      |                        Phone: +49(40)808077-555
    D-20097 Hamburg        |                          FAX: +49(40)808077-556
    Germany	               |              PGP-Key: RSA 2048 Bit ID: 0BB7C8F9
    
    -----BEGIN PGP SIGNATURE-----
    Version: 2.6.2i
    
    iQEVAwUBPf4MaIrEggYLt8j5AQEsfgf9F1N2AswwdizIszzUswgJoTHuaHyIvjGy
    6aZqT5ewi6L31NsN0/nfK+EXNEZoh95Rf9h1XJDKQ+r+jnqSk7JIotNd48flKxet
    nPQkZky2zQDvnRKEcj5iQVGGgSSDaI+7cOzcJ7JEIQlfJAnWT7qp2bYXvFkIojul
    XP4urHDRLoNI9xtp17lVFyp//2LyzfoVQJ6zjKGsRHN0kmLL3Tl+fHCA73TRqBT9
    9x6in2anxiDCcgYZYggFyj0Vk+Bc4NkBLUxpkT7DL3L0n8LbtzHMBOEmZgtcJ5jK
    vNHMYzjEJK6ozx867QsoPbA94Od+/2FvN61qTXjVWE9oRFwHdZLlhA==
    =xP/a
    -----END PGP SIGNATURE-----
    _______________________________________________
    LogAnalysis mailing list
    LogAnalysisat_private
    http://lists.shmoo.com/mailman/listinfo/loganalysis
    



    This archive was generated by hypermail 2b30 : Wed Dec 18 2002 - 18:24:00 PST