Re: Log integrity handling on central logsystem

Patrick Debois <[email protected]>
Newsgroups gmane.comp.sysutils.loganalysis
Message-ID <[email protected]>
Anton Chuvakin wrote:
> Patrick,
>
> I am curious what prompted such integrity requirements - regulation,
> internal policy or something else?  I am sure other list members are
> curious about it as well ...
It's the ICT departement getting paranoid. I guess that is not the first
time ;-(
The customer is financial related but currently we're not looking at
specific regulations.
>
> On 8/21/06, Patrick Debois <[email protected]> wrote:
>> I'm looking for feedback how centralized log solutions handle data
>> integrity; If you would log directly to a central system, that log is
>> the only source. So you would miss something to compare against.
>>
>> -Would you rely on taking checksums of the logs and storing them on
>> another system?
>> -How do you protect yourself from the fact that the central logging is
>> compromised with a still growing logfile?
>> Would you consider signing each log line? Signing within a text file is
>> fairly easy, but what about content stored in a database?
>>
>> My customer is currently looking at Splunk. It seems a great way to go
>> through the logfiles, but I'm not sure that we can fullfill his
>> dataintegrity requirements with it. But then again it does not stand in
>> the way of another solution doing it probable.
>>
>> Patrick
>>
>>
>> _______________________________________________
>> LogAnalysis mailing list
>> [email protected]
>> http://lists.shmoo.com/mailman/listinfo/loganalysis
>>
>
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.