04-22-2004 11:00 AM - edited 02-20-2020 11:21 PM
Not sure if any of you know the Checkpoint real-time log viewer capabilities, but I'm looking for a tool that could do something similar with my PIX real-time logs. I basically want to see everything happenig on my firewall(s) in real time but presented in some readable format with an ability to sort by source/destination IP, services, actions taken etc. Also, what are some good tools for post-mortem log analysis - either open source or commercial?
04-22-2004 11:20 AM
We use webtrends firewall suite to analyze our pix logs.
Here's a link to their web site.
04-23-2004 08:09 PM
I use Microtik syslog http://www.mikrotik.com/download.html
which is free and lets you create filters by text content and group the messages into different folders, apply plugins to specific messages etc..
for example you can create a intranet rule that looks at URLS with /intranet/ and log and save them to a file.
It would be nice if someone can write a plugin that will send a shun command to the pix Microtik provides free the plugin SDK.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide