Re: Analyzing tons of logs

Daniel Cid <[email protected]>
Newsgroups gmane.comp.sysutils.loganalysis
Message-ID <[email protected]>
Hi Chetan,

For the amount of data that you want to analyze, I
agree with Anton, there is no single solution
(commercial or open source) that can handle that.
They will all fail miserably... First of all, you
will have a huge network bandwidth usage, not speaking
about disk space and cpu/memory power to analyze
all of that (specially considering most tools use
regex).

What I would suggest is some form of segmentation or
partition of all this data. You can create one
log analysis "station" for each department or each
section of your company. This way you can perform
your analysis based on the goals of each department.

For example, on your main servers inside the DMZ, you 
can setup a "DMZ" log station, where you can monitor
the logs from there.. This way traffic doesn't need to
leave each segment and the memory/disk/cpu
requirements
can be easily manageable (oh, and it is scalable).


Hope it helps...

--
Daniel B. Cid
dcid ( at ) ossec.net






--- Chetan Gupta <[email protected]> escreveu:

> Dear List Members,
> 
> I am looking for opinion from the experts for a
> particluar problem.
> 
> How do we go about log analysis if we have tons
> (maybe in trillions) of
> logs from lets say tcpdump (raw logs) or some
> firewall (like netscreen or
> pix)?
> What would be the best way to normalize and analyze
> these logs in the
> shortest possible time?
> Import them into a database? Use a commercial
> application like arcsight?
> loglogic? simple text editor like editplus?
> Any suggestions/comments would be appreciated.
> 
> Regards,
> 
> Thanks and Regards,
> ERNST & YOUNG ®
> Ernst & Young Pvt. Ltd
> 
> Chetan Gupta
> Consultant
> Risk and Business Solutions
> FIDS
>
_______________________________________________________
> 
> 
> Mobile:      +91 - 9810718489
> Fax:          +91 - 11 - 2661 1012
> URL:          http://www.ey.com/in
>
_______________________________________________________
> 
> 
> 
>
----------------------------------------------------------
> The information contained in this communication is
> intended solely for the use of the individual or
> entity to whom it is addressed and others authorized
> to receive it.   It may contain confidential or
> legally privileged information.   If you are not the
> intended recipient you are hereby notified that any
> disclosure, copying, distribution or taking any
> action in reliance on the contents of this
> information is strictly prohibited and may be
> unlawful. If you have received this communication in
> error, please notify us immediately by responding to
> this email and then delete it from your system.
> Ernst & Young is neither liable for the proper and
> complete transmission of the information contained
> in this communication nor for any delay in its
receipt.>
_______________________________________________
> LogAnalysis mailing list
> [email protected]
>
http://www.loganalysis.org/mailman/listinfo/loganalysis


__________________________________________________
Fale com seus amigos  de graça com o novo Yahoo! Messenger 
http://br.messenger.yahoo.com/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.