LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices



Reply
 
Search this Thread
Old 06-17-2005, 03:13 AM   #1
ddaas
Member
 
Registered: Oct 2004
Location: Romania
Distribution: Ubuntu server, FreeBsd
Posts: 453

Rep: Reputation: 30
IPTables Log Analyzer


Hi, I want a program which displays in a nice format in the browser iptables logs.
Something like BASE does for snort alerts.

I found IPTables Log Analyzer ( http://www.gege.org/iptables/ ), but it is only a beta version and I don't like this.
There is also sawmill ( www.sawmill.net ). Iíve installed it, but I don't like it very much and it's not free.

Does anybody use IPTables Log Analyzer?

What do you use?
 
Old 06-17-2005, 09:12 AM   #2
hardcorelinux
Member
 
Registered: Jan 2005
Location: India
Distribution: RHEL,CentOS,SUSE,Solaris10
Posts: 183

Rep: Reputation: 31
fwanalog

fwanalog is a shell script that parses and summarizes firewall logfiles.

http://tud.at/programm/fwanalog/


Logrep is a secure multi-platform framework for the collection, extraction, and presentation of information from various log files. It features HTML reports, multi dimensional analysis, overview pages, SSH communication, and graphs, and supports 18 popular systems including Snort, Squid, Postfix, Apache, Sendmail, syslog, ipchains, iptables, NT event logs, Firewall-1, wtmp, xferlog, Oracle listener and Pix.

http://www.l0t3k.net/tools/Loganalys...e-1.4.2.tar.gz

IPTables log analizer (TODO : find a nice name for it) displays Linux 2.4 iptables logs (rejected, acepted, masqueraded packets...) in a nice HTML page (it support rough netfilter logs but also Shorewall and Suse Firewall logs).

http://www.l0t3k.net/tools/Loganalys...er_v0.4.tar.gz

fwanalog is a shell script that parses and summarizes firewall logfiles. It currently (version 0.6.4pre4) understands logs from ipf (tested with OpenBSD 2.8's and 2.9's ipf, also FreeBSD, NetBSD and Solaris 8 with ipf), OpenBSD 3.x pf, Linux 2.2 ipchains, Linux 2.4 iptables, some ZyXEL/NetGear routers and (experimentally) Cisco PIX, Watchguard Firebox and Firewall-One (not NG!) firewalls.

http://www.tud.at/
 
Old 06-18-2005, 03:10 AM   #3
ddaas
Member
 
Registered: Oct 2004
Location: Romania
Distribution: Ubuntu server, FreeBsd
Posts: 453

Original Poster
Rep: Reputation: 30
thanks,
I will try them.
 
Old 06-25-2005, 03:36 AM   #4
Kamikazee
Member
 
Registered: May 2005
Location: Aus
Distribution: SimplyMEPIS 3.3
Posts: 107

Rep: Reputation: 15
Newb Question.

I downloaded the file http://www.l0t3k.net/tools/Loganaly...ce-1.4.2.tar.gz , what do i do with it.. yes it sounds stupid... But i untared it.. then what?
 
Old 06-26-2005, 08:21 AM   #5
ddaas
Member
 
Registered: Oct 2004
Location: Romania
Distribution: Ubuntu server, FreeBsd
Posts: 453

Original Poster
Rep: Reputation: 30
For a new pragram you want to install you have to read:
1) README
2) INSTALL
3)HOWTO

4)Search on GOOGLE
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Iptables Log Analyzer no logs in mysql db! abcampa Linux - Software 1 12-11-2008 03:53 AM
log analyzer MrSandman Linux - Software 2 09-26-2004 02:38 AM
recomend a log analyzer? ziggie216 Linux - Security 1 07-18-2004 06:09 PM
IPtables Log Analyzer from http://www.gege.org/iptables/ brainlego Linux - Software 0 08-11-2003 07:08 AM
Log analyzer? subnet_rx Linux - Security 2 11-06-2001 07:02 AM


All times are GMT -5. The time now is 11:03 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration