RE: SIM solution - Objectives ? (Firewall logging)
Eric Fitzgerald <[email protected]>
| Newsgroups | gmane.comp.sysutils.loganalysis |
|---|---|
| Message-ID | <74735BF202608043B11025A9FAA94389064B5AC3@WIN-MSG-21.wingroup.windeploy.ntdev.microsoft.com> |
mjr wrote: > As far back as I can remember (and that's a long way!) some of > us have been saying that permit log entries are more important > than deny. Generalizing, I think that the same is true of almost ANY audit trail. One minor behavioral difference you might notice is that failures/denies in non-firewall logs tend to be caused more often by misconfiguration than by malice, at least in my experience. YMMV. Eric Fitzgerald Microsoft Corporation