Linux Netfilter discussions
 help / color / mirror / Atom feed
* iptables log analysis tool
@ 2003-09-29 11:40 Afshin Lamei
  2003-09-29 13:29 ` rcriggs
  0 siblings, 1 reply; 5+ messages in thread
From: Afshin Lamei @ 2003-09-29 11:40 UTC (permalink / raw)
  To: netfilter

hi all,
I want to analyse the iptables log files (using LOG and/or ULOG target). 
please help me find a proper tool for this, which can generate some graphs 
using the log files.
regards
afshin

_________________________________________________________________
Add photos to your messages with MSN 8. Get 2 months FREE*. 
http://join.msn.com/?page=features/featuredemail



^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: iptables log analysis tool
  2003-09-29 11:40 iptables log analysis tool Afshin Lamei
@ 2003-09-29 13:29 ` rcriggs
  0 siblings, 0 replies; 5+ messages in thread
From: rcriggs @ 2003-09-29 13:29 UTC (permalink / raw)
  To: Afshin Lamei; +Cc: netfilter

If you don't mind setting up and using mysql use snort/acid.  Great 
combination
for intrustion detection.

Afshin Lamei wrote:

> hi all,
> I want to analyse the iptables log files (using LOG and/or ULOG 
> target). please help me find a proper tool for this, which can 
> generate some graphs using the log files.
> regards
> afshin
>
> _________________________________________________________________
> Add photos to your messages with MSN 8. Get 2 months FREE*. 
> http://join.msn.com/?page=features/featuredemail
>




^ permalink raw reply	[flat|nested] 5+ messages in thread

* RE: iptables log analysis tool
@ 2003-09-29 22:41 George Vieira
  2003-09-30  2:52 ` cc
  0 siblings, 1 reply; 5+ messages in thread
From: George Vieira @ 2003-09-29 22:41 UTC (permalink / raw)
  To: Afshin Lamei, netfilter

>which can generate some graphs using the log files.

this is a small project I'm working on using php (easier/quicker to make changes) and mysql to store the data in even of a reboot/etc...

http://mrtg.citadelcomputer.com.au

some of the above graphs are just scripts while others are using my mysql-iptables.php script to gather the `iptables -L -t $table -v -n -x` information.

Thanks,
____________________________________________
George Vieira
Systems Manager
georgev@citadelcomputer.com.au

Citadel Computer Systems Pty Ltd
http://www.citadelcomputer.com.au

Phone   : +61 2 9955 2644
HelpDesk: +61 2 9955 2698
 

-----Original Message-----
From: Afshin Lamei [mailto:linux_st@hotmail.com]
Sent: Monday, 29 September 2003 9:41 PM
To: netfilter@lists.netfilter.org
Subject: iptables log analysis tool


hi all,
I want to analyse the iptables log files (using LOG and/or ULOG target). 
please help me find a proper tool for this, which can generate some graphs 
using the log files.
regards
afshin

_________________________________________________________________
Add photos to your messages with MSN 8. Get 2 months FREE*. 
http://join.msn.com/?page=features/featuredemail




^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: iptables log analysis tool
  2003-09-29 22:41 George Vieira
@ 2003-09-30  2:52 ` cc
  2003-10-10 19:08   ` Arnt Karlsen
  0 siblings, 1 reply; 5+ messages in thread
From: cc @ 2003-09-30  2:52 UTC (permalink / raw)
  To: George Vieira; +Cc: netfilter

George Vieira wrote:

>>which can generate some graphs using the log files.
> 
> 
> this is a small project I'm working on using php 
> asier/quicker to make changes) and mysql to store the data in
> even of a reboot/etc...
> 
> http://mrtg.citadelcomputer.com.au

That's quite impressive collection of graphs, George.  When
I get the chance I hope to get the logging done on my
firewall.  Currently it's using Snort/acid but right now
having some issues with ACID.  (but that's pretty
much OT here.. :))

But what is On topic is how do you prune your logs?

Thanks








^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: iptables log analysis tool
  2003-09-30  2:52 ` cc
@ 2003-10-10 19:08   ` Arnt Karlsen
  0 siblings, 0 replies; 5+ messages in thread
From: Arnt Karlsen @ 2003-10-10 19:08 UTC (permalink / raw)
  To: netfilter

On Tue, 30 Sep 2003 10:52:30 +0800, 
cc <cc@belfordhk.com> wrote in message 
<3F78EFEE.5040502@belfordhk.com>:

> George Vieira wrote:
> 
> >>which can generate some graphs using the log files.
> > 
> > 
> > this is a small project I'm working on using php 
> > asier/quicker to make changes) and mysql to store the data in
> > even of a reboot/etc...
> > 
> > http://mrtg.citadelcomputer.com.au
> 
> That's quite impressive collection of graphs, George.  When
> I get the chance I hope to get the logging done on my
> firewall.  Currently it's using Snort/acid but right now
> having some issues with ACID.  (but that's pretty
> much OT here.. :))

..I think I can handle an OT url to George's cute 
/etc/mrtg/mrtg.cfg to get us started.  ;-)

> But what is On topic is how do you prune your logs?
> 
> Thanks

..hear, hear!  :-)

-- 
..med vennlig hilsen = with Kind Regards from Arnt... ;-)
...with a number of polar bear hunters in his ancestry...
  Scenarios always come in sets of three: 
  best case, worst case, and just in case.




^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2003-10-10 19:08 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-09-29 11:40 iptables log analysis tool Afshin Lamei
2003-09-29 13:29 ` rcriggs
  -- strict thread matches above, loose matches on Subject: below --
2003-09-29 22:41 George Vieira
2003-09-30  2:52 ` cc
2003-10-10 19:08   ` Arnt Karlsen

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox