well i'm complete beginner when it comes to linux of pretty much any type (other than a few liveCDs) but i've decided on a challenge / project that'll hopefully resolve this.
basically what i'm going to try is to build a centralized event log monitoring system to pull all the logs from the windows servers on our network using linux and only free software. this may be expanded later on to cover IDS, but lets not get ahead of ourselves just yet!
as far as i can see, i'm going to have to break the project down into these sections:
find and install an OS
find some way of pulling event logs of a win2k server
look into database storage - i'm thinking mySQL or similar
develop the reporting and alerting side.
as i'm starting from fresh i could do with as many suggestions / comments as possible really, but my first questions are:
has this been done before?
what flavor of linux would you recommend for this kind of project?
how demanding on the hardware do you think this would be? i've got a few soon to be retired ex-NT4 desktops that i'm thinking of using
have i bitten off more than i can chew?