[logs] Re: Log correlation

From: Anton Chuvakin (anton@private)
Date: Fri Dec 16 2005 - 08:53:53 PST


> Basically the formatting problems are driving me nuts.

Welcome to the world of logs!  :-)

> Can anyone point me in the direction of a tool/methodology I can use
> to do this?
> I'd be most grateful.
Well, here is a funny thing: the whole reasons why this is called "a
challege" is that you have to overcome the above (and other)
problems...

Look at other people's solutions at
http://www.honeynet.org/scans/scan34/ and then create your own. While
doing this, keep in mind that your predecessors did not have the
luxury of access to other solutions...

Best,
--
Anton Chuvakin, Ph.D., GCIA, GCIH, GCFA
     http://www.chuvakin.org
 http://www.securitywarrior.com
_______________________________________________
LogAnalysis mailing list
LogAnalysis@private
http://lists.shmoo.com/mailman/listinfo/loganalysis



This archive was generated by hypermail 2.1.3 : Fri Dec 16 2005 - 11:38:36 PST