Re: [logs] Products for log correlation

From: James Turnbull (james@private)
Date: Wed Apr 07 2004 - 22:05:28 PDT

  • Next message: Chris Petersen: "RE: [logs] Products for log correlation"

    ---- Original Message ----- 
    >I was wondering if anyone knows of a tool for log-file correlation and
    analysis.  By that I mean being able to see in a unified form and arranged
    chronologically log >entries from a variety of disparate and distributed
    systems.  For example, web servers, application servers, operating systems
    and database servers.
    ____________________________________________________________
    
    I use syslog-ng (http://www.balabit.com/products/syslog_ng/) on a central
    logging server to take in logs from from network devices, systems and
    applications.  Then use SEC (http://kodu.neti.ee/~risto/sec/) to do
    correlation, alerting and some analysis.  All running on a Red Hat linux
    box.
    
    Regards
    
    James Turnbull
    _______________________________________________
    LogAnalysis mailing list
    LogAnalysis@private
    http://lists.shmoo.com/mailman/listinfo/loganalysis
    



    This archive was generated by hypermail 2b30 : Wed Apr 07 2004 - 22:08:17 PDT