From: "Pittigher, Raymond - ES" <Raymond.Pittigher@itt.com>
Cc: "linux-audit@redhat.com" <linux-audit@redhat.com>
Subject: Re: log files
Date: Fri, 17 Jun 2011 15:15:14 -0400 [thread overview]
Message-ID: <4DFBA7C2.8070000@itt.com> (raw)
In-Reply-To: <1308337014.7213.10.camel@lcb>
On 06/17/2011 02:56 PM, LC Bruzenak wrote:
> On Fri, 2011-06-17 at 14:32 -0400, Pittigher, Raymond - ES wrote:
> >
> > I also used the au tools (aureport, aufind, etc) but just wanting a
> > average user to view the bad events brings the need of a point a click
> > interface.
>
> Agreed.
>
> > The people that now read the audit events for the windows servers are
> > spoiled by the cornerbowl tool. I tossed together a little script that
> > dumps the audit events into a array, then sorts them and dumps them
> > out but the users want a red background for bad and so on. Before I
> > went crazy trying to put something together I wanted to see what was
> > out in the wild. I guess something that dumps the files into a MySQL
> > tables would be the easiest to work with.
>
> Then what would you use for visualization?
> This week I have been thinking about this very thing myself.
> Good to know others are as well.
>
> LCB
>
> --
> LC (Lenny) Bruzenak
> lenny@magitekltd.com
>
The plan would be to rotate the log at midnight Saturday, use the
aureport to read the file and give it some kind of format, dump the data
into a mysql database, then parse it with php on a apache server with a
firefox front end. Or something like that.
This e-mail and any files transmitted with it may be proprietary and are intended solely for the use of the individual or entity to whom they are addressed. If you have received this e-mail in error please notify the sender.
Please note that any views or opinions presented in this e-mail are solely those of the author and do not necessarily represent those of ITT Corporation. The recipient should check this e-mail and any attachments for the presence of viruses. ITT accepts no liability for any damage caused by any virus transmitted by this e-mail.
next prev parent reply other threads:[~2011-06-17 19:15 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-06-17 18:15 log files Pittigher, Raymond - ES
2011-06-17 18:27 ` LC Bruzenak
2011-06-17 18:32 ` Pittigher, Raymond - ES
2011-06-17 18:57 ` Dominick Grift
[not found] ` <1308337014.7213.10.camel@lcb>
2011-06-17 19:15 ` Pittigher, Raymond - ES [this message]
2011-06-17 19:56 ` LC Bruzenak
2011-06-17 21:33 ` Pittigher, Raymond - ES
2011-06-17 18:38 ` Steve Grubb
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4DFBA7C2.8070000@itt.com \
--to=raymond.pittigher@itt.com \
--cc=linux-audit@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox