RE: open source artificial ignorance-like systems
"Raffael Marty" <[email protected]>
| Newsgroups | gmane.comp.sysutils.loganalysis |
|---|---|
| Message-ID | <[email protected]> |
>> I'd like to offer another perspective.......... what about a 'dictionary'? >> All the OS's have 'some' elements of commonality. Each OS vender has common >> areas. >> Create an analysis of log information that is common and stabilize its 'format', >> even >> to the 'bit' level where applicable, and document it. That is then standard >> parse able. > Indeed - perhaps something along the lines of CVE? From my reading this > seems to be at least partially the intent of the CEE standard that Anton > recently posted. In fact, this is part of CEE. Anton did not disclose the four parts yet. This explains a bit more what CEE is about: http://raffy.ch/blog/ Thanks -raffy -- Raffael Marty, GCIA, CISSP [email protected] Manager Strategic Application Solutions ArcSight, Inc. +1 (408) 864 2662 Security Data Visualization: http://secviz.org ________________________________________________________________ ArcSight 2007 User Conference ~ Protecting Your Business > Register now to save over $800 and receive an ArcSight fleece jacket www.arcsight.com/userconference/ _______________________________________________ LogAnalysis mailing list [email protected] http://www.loganalysis.org/mailman/listinfo/loganalysis