Re: Recommended Log analysis tool (follow up)

"Clayton Dukes \(cdukes\)" <[email protected]>
Newsgroups gmane.comp.sysutils.loganalysis
Message-ID <68A5970254CA1341BE9446715BCB6FD60254DA30@xmb-rtp-201.amer.cisco.com>
Couple of options:
Free tool:
php-syslog-ng, which is a tool that I've contributed a lot of code for. 
More information on it can be found on my NMS Wiki site at
http://nms.gdd.net/index.php/Syslog
The nice thing about this tool is it's ability to provide extended
information on Cisco errors (it has a backend db with 27k error message
descriptions).

Commercial:
LogLogic -- I've been demoing this for a very large customer (~30,000
devices) and it performs extremely well.


      |           |        Clayton Dukes
     |||         |||       NMS Consulting Engineer
   .|||||.     .|||||.     Advanced Services
.:|||||||||:.:|||||||||:.  Office: 919.392.6122
 C i s c o S y s t e m s   MSN: [email protected] 
-----Original Message-----
From: [email protected]
[mailto:[email protected]] On Behalf
Of Mark Jayson R. Alvarez
Sent: Thursday, October 12, 2006 3:05 AM
To: [email protected]
Subject: [logs] Recommended Log analysis tool (follow up)

I just got this information:
The log analysis tool will be used for various firewalls
(fortinet,sonicwall, pix etc.)

My boss wants me to know if the tool can handle these requirements..



________________________________________________________________
* Availability of technical support (ex: 24x7, email, phone, chat, etc.)

* Patch or updating of software is this included or an additonal
expense?

* List of Managed Security Service Providers using the software

* Sizing guidelines - what server specs for X number of clients

* For contingency or redundancy purposes can we mirror the data on
another server and would this entail additional cost?

* Are there steps to backup and resotore data in case of a system crash?

* Would it have a capability to have views for different clients

* Can the reports be exported to a file, if so what formats? PDF, DOC,
etc?

* What reports can be generated:
- # of blocked IPs/Ports
- Source/Dest IP
- IPs, AV, AS report from Fortigate?
- Top Users
- Weekly, Montly, Daily, historical, etc.
- Others PLEASE EXPLORE

* Would the built-in syslog have an ACL facility to avoid being probed
from the public Internet.

* Would it support different logging from various firewall vendor on a
single machine.

* Please list down features outside the above
____________________________________________________________
_______________________________________________
LogAnalysis mailing list
[email protected]
http://lists.shmoo.com/mailman/listinfo/loganalysis
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.