Sysadmin > SecurityAndPentests > LookAtYourLogs

Control your logfiles

syslog and syslog-ng

  • logging via tcp and udp
  • support for stunnel

Syslog analyzers

  • logwatch
  • swatch (opensource)
  • prelude (opensource)
  • Splunk (commercial)
  • kiwi enterprises (commercial)
  • logmucher (shellscript, standardtools, several notification options)
  • fwlogwatch

Weblog analyzers

Proxylog analyzers

  • Calamaris
  • Squij
  • pwebstats

Best Practices

  • sync time via ntp