Firewall Wizards mailing list archives

RE: WebTrends Alternative


From: "Cracknell, Phil" <phil.cracknell () nomura co uk>
Date: Thu, 25 Nov 1999 08:30:44 -0000

Sorry if this has been mentioned but has anyone tried NetCool from
Mircromuse for FW log analysis? 
I know it has loads of modules for various boxes including routers and FW1.
I understand it can be
about 80,000 GBP though. :-( I have a genuine interest in hearing viable
solutions to managing logs for the 30,000 ft view as we have 10 to manage!

As far as the removal and/or archive of logs from firewalls I'm in the
corner with Saravana as far
as better to never have had them on the firewall to start with. Centralised
logging gets rid of one problem but introduces another which is why there is
a real gap in the market for a good log management tool.

 

-----Original Message-----
From: Saravana Ram [mailto:Ram () POP Jaring My]
Sent: 24 November 1999 09:19
To: Firewall-Wizards
Subject: Re: WebTrends Alternative
Importance: Low


I think the most difficult aspect of this would be the question 'how do
you
automate moving the logs off of th box' be it windows NT, Solaris, Nokia,
or
whatever platform checkpoint's currently running on.  Network transfer
from
the
client-side implys some sort of listening service running on the firewall.
Bad.  I haven't looked into a viable cross-platform solution for this
firewall-side.  I've just continued to trudge through the logs with my
perl
script and my sql server.

Instead of a logging device pulling the data from the FW box (which would
require a listening service on the FW), why don't you have the FW push logs
to
a logging device (which would require a listening service on the logger not
the FW). Log data can be pushed in real time (continuously) or in batches
(poll at reasonable intervals).

If tossing log data around in the DMZ is considered too risky, then a serial
(as in RS-232) connection can be made from the FW to the logging device.
This
pathway can't be hacked through unless the logging device is compromised.
Downside, the logging device and the FW have to be placed at the same site.



Current thread: