<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IDS logging and Linux in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ids-logging-and-linux/m-p/337072#M96468</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have configured the logging facielities of PIX Firewall so the firewall can write log messages (alarms and info) om my Slack10.1 server usins linux syslog.&lt;/P&gt;&lt;P&gt;Yesterday I tryed an open source log analyzer, fwanalog, it seems to be a good choice.&lt;/P&gt;&lt;P&gt;If someone else is interested in&lt;/P&gt;&lt;P&gt; &lt;A class="jive-link-custom" href="http://tud.at/programm/fwanalog/" target="_blank"&gt;http://tud.at/programm/fwanalog/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tks for the answer&lt;/P&gt;&lt;P&gt;Giovanni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 15 Apr 2005 06:21:27 GMT</pubDate>
    <dc:creator>giovanni.mellini</dc:creator>
    <dc:date>2005-04-15T06:21:27Z</dc:date>
    <item>
      <title>IDS logging and Linux</title>
      <link>https://community.cisco.com/t5/network-security/ids-logging-and-linux/m-p/337070#M96465</link>
      <description>&lt;P&gt;Hi all.&lt;/P&gt;&lt;P&gt;I have an IDS configured on a PIX515e. &lt;/P&gt;&lt;P&gt;Information messages and Alarm messages generated generated from PIX are logged in a Linux box.&lt;/P&gt;&lt;P&gt;I appreciate any suggestion about some Linux tool that I can use to parse this log.&lt;/P&gt;&lt;P&gt;Tks in advance&lt;/P&gt;&lt;P&gt;Giovanni&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:23:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-logging-and-linux/m-p/337070#M96465</guid>
      <dc:creator>giovanni.mellini</dc:creator>
      <dc:date>2019-03-10T09:23:39Z</dc:date>
    </item>
    <item>
      <title>Re: IDS logging and Linux</title>
      <link>https://community.cisco.com/t5/network-security/ids-logging-and-linux/m-p/337071#M96467</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Giovanni&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what do u mean by linux box here, that meant Linux OS is running on IDS appliance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have VMS or IDM ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Apr 2005 08:52:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-logging-and-linux/m-p/337071#M96467</guid>
      <dc:creator>akhan2004</dc:creator>
      <dc:date>2005-04-14T08:52:37Z</dc:date>
    </item>
    <item>
      <title>Re: IDS logging and Linux</title>
      <link>https://community.cisco.com/t5/network-security/ids-logging-and-linux/m-p/337072#M96468</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have configured the logging facielities of PIX Firewall so the firewall can write log messages (alarms and info) om my Slack10.1 server usins linux syslog.&lt;/P&gt;&lt;P&gt;Yesterday I tryed an open source log analyzer, fwanalog, it seems to be a good choice.&lt;/P&gt;&lt;P&gt;If someone else is interested in&lt;/P&gt;&lt;P&gt; &lt;A class="jive-link-custom" href="http://tud.at/programm/fwanalog/" target="_blank"&gt;http://tud.at/programm/fwanalog/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tks for the answer&lt;/P&gt;&lt;P&gt;Giovanni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Apr 2005 06:21:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-logging-and-linux/m-p/337072#M96468</guid>
      <dc:creator>giovanni.mellini</dc:creator>
      <dc:date>2005-04-15T06:21:27Z</dc:date>
    </item>
    <item>
      <title>Re: IDS logging and Linux</title>
      <link>https://community.cisco.com/t5/network-security/ids-logging-and-linux/m-p/337073#M96470</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have not read this entire paper myself but when I saw your question regarding the analysis of Cisco logs, I though that you could do with all of the information you can get your hands on. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Take a look at this URL and let me know if it helps you in anyway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.networkingunlimited.com/white007.html" target="_blank"&gt;http://www.networkingunlimited.com/white007.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Apr 2005 08:21:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-logging-and-linux/m-p/337073#M96470</guid>
      <dc:creator>darin.marais</dc:creator>
      <dc:date>2005-04-15T08:21:24Z</dc:date>
    </item>
    <item>
      <title>Re: IDS logging and Linux</title>
      <link>https://community.cisco.com/t5/network-security/ids-logging-and-linux/m-p/337074#M96471</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The paper focus on router logs, and I'm interested in PIX logs, but there is some useful information.&lt;/P&gt;&lt;P&gt;Also if I have found a good graphical analyzer (fwanalog), I started to write a shell-based pix log analyzer today.&lt;/P&gt;&lt;P&gt;The primary intent of this analyzer is to help me for a more accurated tuning of ACL in my PIX, according to&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/partner/products/sw/iosswrel/ps1830/products_feature_guide_chapter09186a00800881c0.html" target="_blank"&gt;http://www.cisco.com/en/US/partner/products/sw/iosswrel/ps1830/products_feature_guide_chapter09186a00800881c0.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;and then prevent false positives that can occour.&lt;/P&gt;&lt;P&gt;The report generated must take information about attack only logs, and then generate some stats (eg. source and dest ip, source and dest interface...), so I can create a more accurated ACL on my signature.&lt;/P&gt;&lt;P&gt;I'll post some news about.&lt;/P&gt;&lt;P&gt;Tks &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Apr 2005 09:18:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-logging-and-linux/m-p/337074#M96471</guid>
      <dc:creator>giovanni.mellini</dc:creator>
      <dc:date>2005-04-15T09:18:09Z</dc:date>
    </item>
  </channel>
</rss>

