Re: History of Log Analysis and Modern Search Engine

"Anton Chuvakin" <[email protected]>
Newsgroups gmane.comp.sysutils.loganalysis
Message-ID <[email protected]>
> So how exactly are you defining "searching"?

Awesome question, actually. Let the discussion start.

When I think of log searching I imagine typing a keyword (or a set of
keywords or maybe a regex) into a command line (web form, etc) and
then seeing the log records that match (or NOT match) the above search
expression.

> codes; and you'd probably have clues provided by the way in which the
> compromise was discovered.

Exactly - I think that you can SEARCH for clues later in the
investigation (e.g. do we see the same log traces on other systems,
etc), but won't really help me to analyze how/why the intrusion
occurs.

> change the nature of my position. Whoever is paying me, I would still
> consider artificial ignorance techniques to be search methods, tailored to
> simplify the job of identifying significant events, as well as
> never-before-seen entries.]

Ah, that is much broader definition than mine, for sure.

Mandatory (!) disclosure: I work for LogLogic, as I thought everybody
knows :-) In any case, my corporate affiliation is publicly disclosed
on my site http://www.chuvakin.org

Best,
-- 
Anton Chuvakin, Ph.D., GCIA, GCIH, GCFA
      http://www.chuvakin.org
  http://chuvakin.blogspot.com
    http://www.info-secure.org
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.