OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Looking for a log analysis program

From: FH (fhoustonusa.net)
Date: Fri Nov 06 2009 - 09:42:40 CST


We are potentially having a problem w/ emails being delayed (for example I
received one yesterday evening that was sent 2 days earlier). A quick look at
the headers makes it look like it was the remote system that held on to it for
about 30 hours, however I want to check our logs to make sure there were no
problems on our side as well. As I'm sure you all know digging through the
logs (especially over multiple days/log files) is not fun. What I'm hoping
someone can recommend is a program/script that might be able to help w/ this.
I did find the "Logfile analysis" section on http://www.postfix.org/addon.html
but most of those look to be either old or are not quite what I think I'm
looking for (aka they only give general statistics based on the log files but
don't really help w/ debugging). At quick glance the two that looked the most
hopeful were multitail and AWStats. Does anyone have any experience w/ using
either of these tools in my situation? Does anyone have any other
recommendations for other tools they have found useful for this sort of
debugging? I was hoping there was something w/ a ethereal/wireshark "like"
interface/functionality out there (in particular the search/filtering and the
"conversation" streaming/tracking). Does something like that exist for log
files?

Thanks