OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: Intrusion Detection Logfile Software
From: Wilson, Brian F (Brian.WilsonBNSF.COM)
Date: Tue Oct 10 2000 - 16:42:20 CDT


I would suggest installing an actual IDS.

If your pocketbook is thin, you can go for the obvious no-cost solution of
Snort+aracNIDS?

Snort mixed with aracNIDS will allow you to do what you appear to be hinting
at in your message: Customizable Alerting.

http://www.snort.com
http://www.whitehats.com/ids/ids.html

Hope this helps,
Brian Wilson

-----Original Message-----
From: Wally Hass [mailto:whassNETWORKTHINKING.COM]
Sent: Tuesday, October 10, 2000 12:46 PM
To: FOCUS-IDSSECURITYFOCUS.COM
Subject: Intrusion Detection Logfile Software

Hello,
Does anyone know of any software that will parse your firewall/webserver
logfiles and alert you to any suspicious activity? I use Webtrends for
Firewalls, but find it fairly basic in this area. For example, I would like
to know if anyone tried to connect via PCAnywhere to my server.

It would also be nice if alerted you via e-mail.

Thanks,
Wally Hass
Network Thinking Solutions, Inc.