Log Analysis recommendations
I'm looking for recommendations for a firewall log analysis package.
I am new to firewalls in general so I'd like to port the logs out to a syslog server preferably running on Windows.
I've read about Kiwi and WallWatcher for Windows. I read different comments regarding how pf friendly they are.
I've also read about analog/fwanalog for Linux but my knowledge is weak on this OS and I'd have to build a VM just to do this. It also seems like documentation is old and scarce for these applications.
All recommendations welcome and appreciated.
I got this working with Wall Watcher running on my Windows 7 machine.
Wall Watcher support is set to expire in February 2011. I would like to build a Linux VM and use it for syslog server / dev box. My linux is weak and I'm using this as a project to learn the OS. I'd like some recommendations or a link to a HowTo on what is the easiest way to set this up. Wall Watcher has a great feature that summarizes the syslog data in a more easily readable output. I'd like to have the same capability in Linux. Is there a package out there that can do this? Or script recommendation?