Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-Microsoft
[Top] [All Lists]

RE: Centralizing Event Viewer Logs

Subject: RE: Centralizing Event Viewer Logs
Date: Tue, 29 Jan 2008 12:26:46 -0800
Thanks for all the quick input folks. I will definitely look into each
solution.


-Ron

-----Original Message-----
From: Kurt Buff [mailto:kurt.buff@gmail.com] 
Sent: Tuesday, January 29, 2008 12:24 PM
To: Ron Johnson - Adhost
Cc: focus-ms@securityfocus.com
Subject: Re: Centralizing Event Viewer Logs

There are several alternatives, but I've settled on the Kiwisoft
syslog server (the free version is fine, but the pay version is cheap
and does some very nice extra things) and the IntersectAlliance Snare
syslog client. The Snare client takes each event entry, formats it to
a single line, then sends it to the syslog server. Install it on each
of your machines for which you are monitoring event logs, and it works
nicely.

On Jan 29, 2008 11:51 AM, Ron  Johnson - Adhost <ron@adhost.com> wrote:
Hello List:

I was looking into options that will allow us to centralize Event
Viewer
Logs in an Active Directory domain - can anyone recommend any software
for this? It would be great if we could find a piece of software that
does just this - not a full blown enterprise security solution that
cost$ and does many other things that we wouldn't use it for
necessarily.

Thanks!


<Prev in Thread] Current Thread [Next in Thread>