01-08-2005 09:05 AM - edited 02-20-2020 11:51 PM
I need a program that do a 'real time' parsing of the syslog output from Cisco PIX firewalls:
to perform searches on or filter log records to quickly locate and track events of interest.
(like the CheckPoint SmartView Tracker consolle http://www.checkpoint.com/products/smartcenter/smartcenter_logging.html).
Please can you tell me if tehre's something like that ?
Thanks in advance to all.
01-08-2005 11:04 AM
There are some opensource tools as:
Opensource:
Fwlogsum http://www.ginini.com/software/fwlogsum/
Fwlogwatch http://fwlogwatch.inside-security.de/
Commercial $$ Products:
http://www.sawmill.net/index.html
Windows Versions of syslog are:
http://www.kiwisyslog.com/software_downloads.htm#Download%20Now
http://support.3com.com/software/utilities_for_windows_32_bit.htm
sincerely
Patrick
01-08-2005 12:51 PM
Thanks for the info, but what i really want is a 'real time' syslog function for parsing the output:
with checkpoint smartview tracker for example you can FILTER the logging in 'real time': if you want verify only the packets with a specific source IP address or detination or etc. you can view only this rows on the consolle.
01-08-2005 01:34 PM
With this Products you can di that too:
Commercial $$ Products:
http://www.network-intelligence.com/EN/
http://www.sawmill.net/index.html
You have to invest a little bit of money. But do not forget that for a CheckPoint SmartConsole tou pay also a some x 1000 USD.
sincerely
Patrick
01-09-2005 03:22 AM
hi..
eiqnetwork's firewall analyser is good, as patrick said... you can try a eval version of the same and let us know its performance..
Raj
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide