![]() |
Tutorial 2: Syslog data mining with attached md5sum. AKA "Store 100% of data". Thu, 06 Dec 2007
1. The need. The Hype.There's obviously a need for storing vast amount of logs, and few things today aren't able to log into syslog. So it's just obvious to stumble upon that request every once in a while, and this tutorial illustrates the OSSIM approach at massive syslog data storage. Of course, where you say syslog you can say windows event log, snmp data, whatever generates a big amount of raw data.ComplianceI don't know much yet about all of this compliance stuff (I were lucky, Julio always has been much more knowledgeable on that area than me so I could skip it) but I guess I'll have to start learning, there are just too many people asking for it and I'm getting very curious.From what I've seen, a short list of regulations requiring, or at least strongly recommending a certain amount of raw data storage and reports are:
Centralized loggingMaybe the need is pure sysadmin's lazyness. You want to be able to answer to questions you get asked by your management / customers in the easiest possible way.I heard this from a guy a couple of days ago: the more information about your network you've got, the more answers you can give, and that's exactly what SIM/SEM systems are good at. Data miningThis is a bit redundant with the previous entry, but there are people that just don't care about exact data, but they're in desperate need of colorful graphs in order to be able to keep their bosses calm. Well, having logs from everything in your network allows for easy colorful report generation with little knowledge of the underlying data. The worthyness of those reports in the end will be highly questionable of course.::read more
posted at: 20:10 | path: /ossim/tutorials | permanent link to this entry | 11 comments | OSSIM Mobile now available ;-) Sat, 01 Dec 2007 Well, kindof at least... Since Apple's iPhone is basically a stripped down MacosX and it has some nice toys to play with, I thought I'd give the provided python port a try and fire up the OSSIM agent. As expected everything worked like a charm and getting ossim up & running was very easy. Here is the rest of it. ::read more
posted at: 18:43 | path: /ossim/plugins | permanent link to this entry | 3 comments | |
Categories
/ (62) Dominique Karg (feel free to get in touch) Friend's blogs:
Archives
2009-Dec Tags | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||



