Log Analysis recommendations



  • Hi,

    I'm looking for recommendations for a firewall log analysis package.

    I am new to firewalls in general so I'd like to port the logs out to a syslog server preferably running on Windows.

    I've read about Kiwi and WallWatcher for Windows. I read different comments regarding how pf friendly they are.

    I've also read about analog/fwanalog for Linux but my knowledge is weak on this OS and I'd have to build a VM just to do this. It also seems like documentation is old and scarce for these applications.

    All recommendations welcome and appreciated.



  • Update:
    I got this working with Wall Watcher running on my Windows 7 machine.

    Question,
    Wall Watcher support is set to expire in February 2011. I would like to build a Linux VM and use it for syslog server / dev box. My linux is weak and I'm using this as a project to learn the OS. I'd like some recommendations or a link to a HowTo on what is the easiest way to set this up. Wall Watcher has a great feature that summarizes the syslog data in a more easily readable output. I'd like to have the same capability in Linux. Is there a package out there that can do this? Or script recommendation?


Log in to reply