What factors should we consider in selecting security-log-auditing software?
Information Week has a small blurb on
What factors should we consider in selecting security-log-auditing software?
I have also written here before on Five Factors of Logging Infrastructure.