Boston Linux & Unix (BLU) Home | Calendar | Mail Lists | List Archives | Desktop SIG | Hardware Hacking SIG
Wiki | Flickr | PicasaWeb | Video | Maps & Directions | Installfests | Keysignings
Linux Cafe | Meeting Notes | Blog | Linux Links | Bling | About BLU

BLU Discuss list archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Interpreting audit logs?



 Scott Ehrlich wrote: 
> How, then do I properly and successfully review the audit log entries... 

Not answering your precise question, but the general purpose answer for 
how best to review logs for ongoing monitoring is to use a log analysis 
tool, which will sift through the data and present it in summary form, 
while also bringing to your attention any unusual or unexpected entries. 

I use logwatch (http://www2.logwatch.org:81/) for this purpose. Set to 
run at low detail daily, which alerts of error conditions, and medium 
detail weekly, which summarizes statistics. 

  -Tom 

-- 
Tom Metro 
Venture Logic, Newton, MA, USA 
"Enterprise solutions through open source." 
Professional Profile: http://tmetro.venturelogic.com/

-- 
This message has been scanned for viruses and 
dangerous content by MailScanner, and is 
believed to be clean. 

_______________________________________________ 
Discuss mailing list 
[hidden email] 
http://lists.blu.org/mailman/listinfo/discuss
 


BLU is a member of BostonUserGroups
BLU is a member of BostonUserGroups
We also thank MIT for the use of their facilities.

Valid HTML 4.01! Valid CSS!



Boston Linux & Unix / webmaster@blu.org