
Security Log Management
Identifying Patterns in the Chaos
Jacob Babbin(Author)
Syngress (Publisher)
Published on 27. January 2006
Book
Paperback/Softback
350 pages
978-1-59749-042-9 (ISBN)
Description
This book teaches IT professionals how to analyze, manage, and automate their security log files to generate useful, repeatable information that can be use to make their networks more efficient and secure using primarily open source tools. The book begins by discussing the "Top 10? security logs that every IT professional should be regularly analyzing. These 10 logs cover everything from the top workstations sending/receiving data through a firewall to the top targets of IDS alerts. The book then goes on to discuss the relevancy of all of this information. Next, the book describes how to script open source reporting tools like Tcpdstats to automatically correlate log files from the various network devices to the "Top 10? list. By doing so, the IT professional is instantly made aware of any critical vulnerabilities or serious degradation of network performance. All of the scripts presented within the book will be available for download from the Syngress Solutions Web site.
Almost every operating system, firewall, router, switch, intrusion detection system, mail server, Web server, and database produces some type of "log file.? This is true of both open source tools and commercial software and hardware from every IT manufacturer. Each of these logs is reviewed and analyzed by a system administrator or security professional responsible for that particular piece of hardware or software. As a result, almost everyone involved in the IT industry works with log files in some capacity.
Almost every operating system, firewall, router, switch, intrusion detection system, mail server, Web server, and database produces some type of "log file.? This is true of both open source tools and commercial software and hardware from every IT manufacturer. Each of these logs is reviewed and analyzed by a system administrator or security professional responsible for that particular piece of hardware or software. As a result, almost everyone involved in the IT industry works with log files in some capacity.
More details
Language
English
Place of publication
Rockland, MA
United States
Target group
Professional and scholarly
System administrator or security professionals, IT professionals.
Product notice
Paperback (trade)
Dimensions
Height: 226 mm
Width: 182 mm
Thickness: 29 mm
Weight
506 gr
ISBN-13
978-1-59749-042-9 (9781597490429)
Copyright in bibliographic data and cover images is held by Nielsen Book Services Limited or by the publishers or by their respective licensors: all rights reserved.
Schweitzer Classification
Other editions
Additional editions

E-Book
01/2006
Elsevier
€39.95
Available for download
Person
Author
Contractor with a government agency filling the role of Intrusion Detection Team Lead
Content
Introduction to Security Log Management; The Top 10 Security Logs; IDS Reporting; Firewall Reporting; Systems and Network Device Reporting; Creating a Reporting Infrastructure; Scalable, Enterprise solutions (ESM deployments); Planning for the Future