Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Basics
[Top] [All Lists]

Re: Logging

Subject: Re: Logging
Date: Mon, 21 Jan 2008 08:43:08 -0500
Are you wanting to purchase or use free products? If you have the money, as it is expensive but worth it for large environments, the Activeworx product from Crosstech is an excellent product. You can capture logs for all types of devices right into a database or databases and it also has nice reporting for Sox related issues amongst others. They also offer a nice correlation engine you can purchase with it to correlate attacks. I think you can trial it for 15 days or so. The only drawbacks is that it only runs on Windows Server and it is a challenge to set up, but once up it is really nice.

If you want free, splunk is just ok for viewing logs (not very nice to look at), or look into adventnet products. They offer free for small offices. I dont think prices are bad for larger environments either. You can also always go with syslog-ng to capture and sort log information centrally then view with free splunk or some other log viewer.

Hope that helps a little!



infolookup@gmail.com wrote:
I am interested in seeing some feed back on this topic, cause I am looking into doing this too.

Sent via BlackBerry from T-Mobile

-----Original Message-----
From: "Krzyston, Randy" <RandyK@gen-probe.com>

Date: Fri, 18 Jan 2008 10:19:21 To:<security-basics@securityfocus.com>
Cc:<listbounce@securityfocus.com>
Subject: Logging



We are looking to implement a syslog server. It needs to not only be capable of storing logs ,but also detailed reporting for things such as SOX. I've looked at LogLogic's products. I also heard about Kiwi, but have not experience with it.

Any comments?


Randy




<Prev in Thread] Current Thread [Next in Thread>