1 |
Hello Patrick, |
2 |
|
3 |
> I'm going to setup a central syslog server for Linux and windows machines, |
4 |
> but whats the best program to examin these logs, and send out email alerts |
5 |
> to users ? |
6 |
|
7 |
I am currently using two programs to monitor my logs: |
8 |
|
9 |
swatch - http://swatch.sourceforge.net/, which I use for monitoring realtime |
10 |
events in my log files, like failed logins, administrator/root logins, etc. |
11 |
|
12 |
logwatch - http://www.logwatch.org/, which I use for generating daily reports |
13 |
on the logged information. |
14 |
|
15 |
Is this perfect, no, but a start. Some of the other programs I have looked as |
16 |
but not really implemented are: |
17 |
|
18 |
sec - http://simple-evcorr.sourceforge.net/, which does some event analysis. |
19 |
|
20 |
tenshi - http://tenshi.gentoo.org, which is a Gentoo project for log parsing |
21 |
and notification. |
22 |
|
23 |
There are some event analysis tools, but I have not even considered looking at |
24 |
them yet, like: |
25 |
|
26 |
OSSIM - http://www.ossim.net |
27 |
|
28 |
OpenSIMS - http://www.opensims.org |
29 |
|
30 |
A good site is http://www.loganalysis.org |
31 |
|
32 |
Sean |
33 |
|
34 |
> |
35 |
> It seems that there are not so many opensource solutions. |
36 |
> |
37 |
> TIA |
38 |
> |
39 |
> -- |
40 |
> This is Unix-Land. In quiet nights, you can hear the Windows machines |
41 |
> reboot. |
42 |
|
43 |
-- |
44 |
Sean Higgins, sean@×××××××.com |
45 |
http://www.systura.com - "Where information becomes knowledge." |
46 |
-- |
47 |
gentoo-user@g.o mailing list |