Re: How to define Log, Event, and Alert?
"Anton Chuvakin" <[email protected]> Wed, 23 Jul 2008 14:33:55 -0700
| Newsgroups | gmane.comp.sysutils.loganalysis |
|---|---|
| Message-ID | <[email protected]> |
What if it is completely devoid of "interest," boring as ... as a log? ;-) I like the definition, but interest might be determined later, is the eye of the beholder, etc. I think we can't go beyond "smth that happened", however generic it might be. "Occurence on an information system?" I think the "classic" def of an event was "observable occurence", but it is too academic to my taste... On 7/23/08, Andrew Hay <[email protected]> wrote: > How about referring to an event as: > > "A discrete, distinct, and discernible occurrence of interest within > an environment" > > Thoughts? > > On Wed, Jul 23, 2008 at 5:21 PM, Anton Chuvakin <[email protected]> wrote: >>> I'm good with the definitions, except for the concept of an "event": >> >> Same thing. Event is not necessarily "a state change." It is a >> broader thing, basically, "something that happened" (even though a >> state is the same - e.g. backup is proceeding, attack was seen, etc) >> >> >>> >>>> Event: >>>> A discrete, distinct, and discernible state change in an >>>> environment. >>> >>> In some aspects, state changes such as processes dieing or starting >>> are surely events, but I also think that some logs which don't indicate >>> a state change such as login failures, port scanning, intrusion >>> detection logs, and so on are noteworthy and worth alerting on. >>> >>> Ron >>> >>> >>> >>> >>> >>> >>> >>> _______________________________________________ >>> LogAnalysis mailing list >>> [email protected] >>> http://www.loganalysis.org/mailman/listinfo/loganalysis >>> >> >> >> >> -- >> Anton Chuvakin, Ph.D., GCIA, GCIH, GCFA >> http://www.chuvakin.org >> http://chuvakin.blogspot.com >> http://www.info-secure.org >> _______________________________________________ >> LogAnalysis mailing list >> [email protected] >> http://www.loganalysis.org/mailman/listinfo/loganalysis >> > > > > -- > Andrew Hay > Security+, CCSE Plus, RHCE, GSEC, GCIA, GCIH, CISSP > blog: http://www.andrewhay.ca > email: [email protected] > twitter: andrewsmhay > profile: http://www.linkedin.com/in/andrewhay > -- Anton Chuvakin, Ph.D., GCIA, GCIH, GCFA http://www.chuvakin.org http://chuvakin.blogspot.com http://www.info-secure.org