OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: Intrusion Detection Logfile Software
From: Ron Gula (rgulaNETWORK-DEFENSE.COM)
Date: Tue Oct 10 2000 - 15:54:27 CDT


At 10:46 AM 10/10/00 -0700, you wrote:
>Hello,
>Does anyone know of any software that will parse your firewall/webserver
>logfiles and alert you to any suspicious activity? I use Webtrends for
>Firewalls, but find it fairly basic in this area. For example, I would like
>to know if anyone tried to connect via PCAnywhere to my server.
>
>It would also be nice if alerted you via e-mail.
>

Hi Wally,

The Dragon Squire product which we sell along with the Dragon
Sensor network IDS will parse access_log files and many different
firewall logs. It also parses system log files such as the
/var/log/messages file and perform MD5 file integrity checking.
Multiple Dragon Squire agents can also be managed from one
console.

Ron Gula
VP IDS Product
Enterasys Networks
http://www.enterasys.com
http://www.securitywizards.com