OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
ISA Log file analysis software - suggestions?

From: Gary Palmer (gpalmereducause.edu)
Date: Thu Apr 10 2003 - 15:10:52 CDT


Our small business uses Microsoft's ISA server as both a firewall system
and Web proxy. We have historically used Webtrends (NetIQ) products to
analyze hits to our Web site. To keep things consistent, we bought the
Webtrends Firewall Suite to analyze firewall logs for incoming and
outgoing firewall and Web traffic, but learned after the fact from NetIQ
support that, unfortunately, the Firewall Suite doesn't support for the
analysis of incoming Web activity logs created by ISA (even though ISA
is listed as one of the log types to be analyzed), and found that, sure
enough, it doesn't work correctly with ISA Web proxy logs.

I'm looking for product suggestions. We'd like to find analysis software
that works with ISA Web proxy logs, and will accurately count web page
hits, page views, and which allows filtering to zero in on the activity
for specific pages and areas of the Web site. If it also does security
analysis for ISA logs, so much the better, although the Firewall Suite
actually does a good job in that area. Has anyone found an analysis tool
that they're particularly happy with?

Please feel free to respond to me directly if you prefer.

Thanks in advance.

Gary

-------------------------------------------------
Gary Palmer
Security Administrator
EDUCAUSE
gpalmereducause.edu
(303) 939-0310

----------------------------------------------------------------------
Block Spam, Smut & Viruses
SurfControl E-mail Filter for SMTP & Exchange leverages multiple layers of
technology including filtering embedded and attached file content. Rid your
enterprise of unwanted content.
http://www.securityfocus.com/SurfControl-focus-ms2
Download your free fully functional trial, complete with 30-days of free
technical support.
----------------------------------------------------------------------