Re: SIM solution - Objectives ?
"Mikael Kuisma" <[email protected]>
| Newsgroups | gmane.comp.sysutils.loganalysis |
|---|---|
| Message-ID | <[email protected]> |
Hi Saudi, To detect changes in your network configuration based on firewall logs, you can use the ASDIC network traffic analysis system. It registers the standard traffic and reports changes, based on whatever criteria of you choice. Works fine of both Stonegate and Firewall-1 logs. It uses a quite neat (and as far I know, unique) mechanism of aggregating relating log entries, keeping the output short and concise. Read more and download it for free from http://info.ping.se Disclaimer - I am directly involved with the development of ASDIC. Regards, Mikael Kuisma, Ping On 6/2/07, saudi sans <[email protected]> wrote: > > Hi Dave > > That is a very useful link. > > Does anyone know a similar resource for other Firewalls like > Checkpoint and Stonegate which has the details of Audit logs - their > details. This is basically for writing rules in my SIM software for > filtering events-of-interest > > _______________________________________________ LogAnalysis mailing list [email protected] http://www.loganalysis.org/mailman/listinfo/loganalysis