[logs] Re: Log integrity handling on central logsystem

From: Marcus J. Ranum (mjr@private)
Date: Fri Sep 01 2006 - 07:21:40 PDT


Christopher L. Petersen wrote:
>Hey Marcus.  I hear what you're saying but I have to wonder if log
>management solutions, whether commercial or homegrown, will eventually
>be held to standards higher than what they are today. 

I hope so! But, seriously, I think it's going to be quite a while before
organizations graduate from simply letting the windows logs "go"
to aggregating them. And probably a decade before there's any
kind of audit standard that actually includes _LOOKING_ at the
logs. Have you noticed that, right now, everyone is focused on
installing technology that aggregates logs and then skims data
out of the vast aggregated mass, so that people only have to look
at the very tiny tip of the iceberg? See what's wrong with that
picture?

mjr. 

_______________________________________________
LogAnalysis mailing list
LogAnalysis@private
http://lists.shmoo.com/mailman/listinfo/loganalysis



This archive was generated by hypermail 2.1.3 : Fri Sep 01 2006 - 11:12:59 PDT