Gentoo Archives: gentoo-user

From: Sean Higgins <sean@×××××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Central syslog server and then
Date: Tue, 20 Sep 2005 22:46:18
Message-Id: 200509201705.32398.sean@systura.com
In Reply to: [gentoo-user] Central syslog server and then by Patrick Marquetecken
1 Hello Patrick,
2
3 > I'm going to setup a central syslog server for Linux and windows machines,
4 > but whats the best program to examin these logs, and send out email alerts
5 > to users ?
6
7 I am currently using two programs to monitor my logs:
8
9 swatch - http://swatch.sourceforge.net/, which I use for monitoring realtime
10 events in my log files, like failed logins, administrator/root logins, etc.
11
12 logwatch - http://www.logwatch.org/, which I use for generating daily reports
13 on the logged information.
14
15 Is this perfect, no, but a start. Some of the other programs I have looked as
16 but not really implemented are:
17
18 sec - http://simple-evcorr.sourceforge.net/, which does some event analysis.
19
20 tenshi - http://tenshi.gentoo.org, which is a Gentoo project for log parsing
21 and notification.
22
23 There are some event analysis tools, but I have not even considered looking at
24 them yet, like:
25
26 OSSIM - http://www.ossim.net
27
28 OpenSIMS - http://www.opensims.org
29
30 A good site is http://www.loganalysis.org
31
32 Sean
33
34 >
35 > It seems that there are not so many opensource solutions.
36 >
37 > TIA
38 >
39 > --
40 > This is Unix-Land. In quiet nights, you can hear the Windows machines
41 > reboot.
42
43 --
44 Sean Higgins, sean@×××××××.com
45 http://www.systura.com - "Where information becomes knowledge."
46 --
47 gentoo-user@g.o mailing list