| Author |
Message |
MrGrumpy
|
|
|
Post subject: kiwi Syslog
Posted: May 28, 2004 - 08:11 AM
|
|
Bug Member

Joined: May 19, 2004
Posts: 34
Location: Fife,Scotland
Status: Offline
|
|
Anyone know if this or any other program can take the firewall hits and sort them out into like a top 10 of listed IPs based on number of hits and which port was attacked ? Although 445 and 135 seems the most popular  |
|
|
| |
|
|
|
 |
eusty
|
|
Post subject:
Posted: May 28, 2004 - 09:01 AM
|
|
Bug Admin

Joined: Aug 28, 2003
Posts: 1101
Location: King's Lynn
Status: Offline
|
|
Yes there is......but I don't know what it's called!!!
I know Andy has played with it in the past ( ) so I'm sure he'll inform you  |
_________________ Steve
www.uk-bug.net
|
| |
|
|
|
 |
AndyJenkins
|
|
Post subject:
Posted: May 28, 2004 - 11:13 AM
|
|
Bug Admin
Joined: Aug 28, 2003
Posts: 432
Status: Offline
|
|
Sure have .. have a ganders at Sawmill.
Ignore the impression from the website that its a web server analysis tool - it does syslog'ed stuff too .. and is quite good at it too after you've gone through the pain of getting it setup. |
|
|
| |
|
|
|
 |
MrGrumpy
|
|
Post subject:
Posted: May 28, 2004 - 12:24 PM
|
|
Bug Member

Joined: May 19, 2004
Posts: 34
Location: Fife,Scotland
Status: Offline
|
|
well downloaded it ran it, and it no working Went through all the setup procedure and then it said no log format found even though I set it up. Now i get no server found messages. Anything else ??
Ok to add, restarted the service and it comes up now however ?? What format works with this ? Tried several in Kiwi and Sawmill does not recognise any so far . PITA |
|
|
| |
|
|
|
 |
AndyJenkins
|
|
Post subject:
Posted: May 28, 2004 - 12:53 PM
|
|
Bug Admin
Joined: Aug 28, 2003
Posts: 432
Status: Offline
|
|
Attach / PM me an example log you have, and I'll try it.
Stating the obvious, but I guess your method is sysloged into kiwi, then Kiwi is saving the file right ? Its this kiwi generated file you import into Sawmill. |
|
|
| |
|
|
|
 |
|
|