[logs] Re: Check Point FW1 Log

From: Christina Noren (cfrln@private)
Date: Mon Feb 20 2006 - 11:55:21 PST


Splunk has a cmdline option as part of its free version now if what  
you're after is keyword searching. It handles any format ascii logs.

www.splunk.com for download

On Feb 19, 2006, at 1:41 AM, Joost van Baal wrote:

> Op za 18 feb 2006 om 01:14:06 -0800 schreef Greg Dotoli:
>
>> Does anyone know of a command line tool for searching
>> through  a proprietary FW1 log?
>> We want to setup a stand alone station for searching
>> through syslogs and log files from various firewalls.
>> I can't seem to find a tool for the FW1 binary log. I
>> know checkpoint allows command level searching on
>> the active firewall, but these files have been moved
>> to a central server.
>>
>> Now we need to move the binary logs to our station for
>> log analysis.
>>
>
> Perhaps Torsten Fellhauer's fw1-loggrabber at
> http://sourceforge.net/projects/fw1-loggrabber is of use to you.
> fw1-loggrabbers output can be analyzed by LogReport's Lire.
>
> HTH, Bye,
>
> Joost
>
> _______________________________________________
> LogAnalysis mailing list
> LogAnalysis@private
> http://lists.shmoo.com/mailman/listinfo/loganalysis
>

_______________________________________________
LogAnalysis mailing list
LogAnalysis@private
http://lists.shmoo.com/mailman/listinfo/loganalysis



This archive was generated by hypermail 2.1.3 : Tue Feb 21 2006 - 19:09:07 PST