SLAC – Secure Log File Analysis Service

| Posted in General Techologies

Automated and Secure Log File Analysis Service – SLAC. An Intelligent Log File Analysis System to keep you informed about your Web Servers safety and your Checkpoint FW-1. No software required! Interesting idea…I am just not sure that administrators will feel safe enough to send their corporate logs to an external service like this. Obviously [...]

More...
January 26th, 2005 | Jian Zhen | 1 Comment

DON’T Ignore Lowly Log Analysis

| Posted in General Techologies

DON’T Ignore Lowly Log Analysis by Douglas Schweitzer. Ever take a look at the computer security hardware and software products available these days? The number of them is staggering. They promise to (and for the most part do) help keep your workstations and servers secure. Nonetheless, although these routers, firewalls and intrusion-detection and -prevention systems [...]

More...
January 24th, 2005 | Jian Zhen | No Comments

Looking for a Log Analyst

| Posted in General Techologies

My company, LogLogic, is looking to fill a “log analyst” position. Title to be decided but the requirements are – understanding the log formats and transport mechanisms – researching different log formats to identify common categories (to help design the back end) – parsing and normalizing the logs for the necessary information, based on requirements [...]

More...
January 19th, 2005 | Jian Zhen | No Comments

Looking for log samples

| Posted in General Techologies

I am looking for some log samples to help us test our product. It would be much appreciated if you can help with any of them. You can send them directly to me at zhenjl@gmail.com. The log samples you send will remain confidential and will be used ONLY for internal testing. If you are ok [...]

More...
January 17th, 2005 | Jian Zhen | No Comments

Gmail accounts

| Posted in General Techologies

Anyone want a gmail account? Email me if you are interested.

More...
January 17th, 2005 | Jian Zhen | No Comments

Security information management: is it either software or managed security services?

| Posted in General Techologies

Security information management: is it either software or managed security services? Man, does this really worth $3395!!?? By year-end 2004 vendors will have generated $174m from the security information management software market. The strong drivers for this solution will propel the market forward over the next four years, at a CAGR of 35%, to reach [...]

More...
January 15th, 2005 | Jian Zhen | No Comments

Dashboard conversations

| Posted in General Techologies

I was talking to a couple of friends (a CSO and a security architect) about the usefulness of current dashboards the other day at Patxi’s. One of the complains is that the current dashboards are all flashy stuff and they don’t provide any explanation of what you see in the charts or graphs, nor do [...]

More...
January 13th, 2005 | Jian Zhen | No Comments

Retrieving file-based logs from Windows servers

| Posted in General Techologies

The following is what I posted to the loganalysis mailing list. The original question was regarding how to retrieve Web server logs (Apache for Windows) and Application specific logs (written in text format). You can accomplish this in a couple of ways. One, you can write a batch script on Windows box and use AT [...]

More...
January 9th, 2005 | Jian Zhen | 1 Comment

Apache Logging via Syslog

| Posted in General Techologies

I think one of the most frequently asked questions in log management is how to get the Apache logs to the log management server. Here are a couple workarounds. https://lists.balabit.hu/pipermail/syslog-ng/2001-February/001208.html http://www.precision-guesswork.com/sage-guide/apache.html The first option is probably what most people are looking for. Other options include transferring of the Apache logs after it has been rotated. [...]

More...
January 7th, 2005 | Jian Zhen | No Comments

The war on leaked intellectual property

| Posted in General Techologies

My article on “War on IP Leakage” has been posted on ComputerWorld.

More...
January 6th, 2005 | Jian Zhen | 1 Comment