RE: [logs] most popular reports...?

From: Kohlenberg, Toby (toby.kohlenberg@private)
Date: Thu Aug 19 2004 - 22:38:22 PDT


>-----Original Message-----
>From: 
>loganalysis-bounces+toby.kohlenberg=intel.com@private 
>[mailto:loganalysis-bounces+toby.kohlenberg=intel.com@private
>oo.com] On Behalf Of Anton A. Chuvakin
>Sent: Thursday, August 19, 2004 7:58 PM
>To: Marcus J. Ranum; loganalysis@private
>Subject: Re: [logs] most popular reports...?
>
>>Here's my list:
>>	N should be considered a settable parameter
>
>Oh, my - you surely missed something, Marcus. Where is all the:
>
>-  Bottom N Accesed Ports
>-  Bottom N Event Types
>-  Bottom N ...
>
>Event rarity rules!

Definitely. In fact I'll take a second and mention my favorite use for
statistical operators- telling me about anything that changes
significantly.
Don't tell me when you see some random event, tell me when the number of
events of a specific type increases by 50%. That give me 0->1, 1->2,
2->3,
3->5, 100->150, etc...
Which means that I catch all the rare events and I catch the large
changes
in the noisy events.

t
_______________________________________________
LogAnalysis mailing list
LogAnalysis@private
http://lists.shmoo.com/mailman/listinfo/loganalysis



This archive was generated by hypermail 2.1.3 : Fri Aug 20 2004 - 00:21:02 PDT