03-11-2010
06:44 AM
- last edited on
03-25-2019
05:44 PM
by
ciscomoderator
Hey All,
i am in need of working logfile analyzer for ASA and/or FWSM series log messages. I would prefer a linux based open source tool with the capabilities to highlight false logins and pipe the output into some kind of mail alert component. A huge plus would be the ability to parse Secure ACS output as well.
Thanks for reading
Roble
03-11-2010 06:57 AM
check out http://www.rsyslog.com/
-KS
03-11-2010 07:07 AM
Hey KS,
thanks for the quick answer. rsyslog looks like another logdeamon and my configuration with syslog-ng works out fine so far.
Maybe i overlooked something in the rsyslog docs but i need a log parser not a log deamon.
Roble
03-11-2010 07:13 AM
Sorry my bad. check this out: http://www.loganalysis.org/
We just use cat, grep, sed, awk and uniq to parse through syslogs.
-KS
03-11-2010 09:51 AM
Cisco MARS can also do it and run reports for you.
PK
03-12-2010 12:42 AM
Hey PK,
i would like a MARS but unfortunately this solution is a bit oversized for the current demand. I actually found something which works pretty well allthough its a retail product.
http://www.manageengine.com/products/firewall/
Roble
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide