Gentoo Archives: gentoo-user

From: gentuxx <gentuxx@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Practical log reviewing
Date: Tue, 22 Aug 2006 03:59:14
Message-Id: 44EA7FC0.50902@gmail.com
In Reply to: [gentoo-user] Practical log reviewing by Grant
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 Grant wrote:
5 > Does anyone know of a practical way to review all the various logs on
6 > the system each day? Does it just come down to a brisk scroll through
7 > the previous day's rotated logs?
8 >
9 > - Grant
10
11 Depending on what you're requirements are, try OSSEC-HIDS
12 (www.ossec.net). I've been using it for a couple weeks now and it's
13 pretty handy. The longer I use it, the more I add to it, the better it
14 is. Unfortunately there isn't an ebuild for it (yet). But it's really
15 easy to install. Plus it does a lot more than just log monitoring.
16
17 As far as other tools that might be available, you could try swatch or
18 any of the other ploethera of tools that are out there. It really
19 depends on why you want to review your logs: curiosity? security?
20 regulation compliance?
21
22 - --
23 gentux
24 echo "hfouvyyAhnbjm/dpn" | perl -pe 's/(.)/chr(ord($1)-1)/ge'
25
26 gentux's gpg fingerprint ==> 5495 0388 67FF 0B89 1239 D840 4CF0 39E2
27 18D3 4A9E
28 -----BEGIN PGP SIGNATURE-----
29 Version: GnuPG v1.4.5 (GNU/Linux)
30
31 iD8DBQFE6n/ATPA54hjTSp4RAvenAKDa0tboAerF4tFVOocd8mAWu1waOwCgnpfJ
32 nG8xqnZsCBY+hALJX1wzX9I=
33 =QEmq
34 -----END PGP SIGNATURE-----
35 --
36 gentoo-user@g.o mailing list

Replies

Subject Author
[gentoo-user] Re: Practical log reviewing reader@×××××××.com