LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
Search this Thread
Old 06-17-2005, 02:13 AM   #1
ddaas
Member
 
Registered: Oct 2004
Location: Romania
Distribution: Ubuntu server, FreeBsd
Posts: 452

Rep: Reputation: 30
IPTables Log Analyzer


Hi, I want a program which displays in a nice format in the browser iptables logs.
Something like BASE does for snort alerts.

I found IPTables Log Analyzer ( http://www.gege.org/iptables/ ), but it is only a beta version and I don't like this.
There is also sawmill ( www.sawmill.net ). Iíve installed it, but I don't like it very much and it's not free.

Does anybody use IPTables Log Analyzer?

What do you use?
 
Old 06-17-2005, 08:12 AM   #2
hardcorelinux
Member
 
Registered: Jan 2005
Location: India
Distribution: RHEL,CentOS,SUSE,Solaris10
Posts: 183

Rep: Reputation: 31
fwanalog

fwanalog is a shell script that parses and summarizes firewall logfiles.

http://tud.at/programm/fwanalog/


Logrep is a secure multi-platform framework for the collection, extraction, and presentation of information from various log files. It features HTML reports, multi dimensional analysis, overview pages, SSH communication, and graphs, and supports 18 popular systems including Snort, Squid, Postfix, Apache, Sendmail, syslog, ipchains, iptables, NT event logs, Firewall-1, wtmp, xferlog, Oracle listener and Pix.

http://www.l0t3k.net/tools/Loganalys...e-1.4.2.tar.gz

IPTables log analizer (TODO : find a nice name for it) displays Linux 2.4 iptables logs (rejected, acepted, masqueraded packets...) in a nice HTML page (it support rough netfilter logs but also Shorewall and Suse Firewall logs).

http://www.l0t3k.net/tools/Loganalys...er_v0.4.tar.gz

fwanalog is a shell script that parses and summarizes firewall logfiles. It currently (version 0.6.4pre4) understands logs from ipf (tested with OpenBSD 2.8's and 2.9's ipf, also FreeBSD, NetBSD and Solaris 8 with ipf), OpenBSD 3.x pf, Linux 2.2 ipchains, Linux 2.4 iptables, some ZyXEL/NetGear routers and (experimentally) Cisco PIX, Watchguard Firebox and Firewall-One (not NG!) firewalls.

http://www.tud.at/
 
Old 06-18-2005, 02:10 AM   #3
ddaas
Member
 
Registered: Oct 2004
Location: Romania
Distribution: Ubuntu server, FreeBsd
Posts: 452

Original Poster
Rep: Reputation: 30
thanks,
I will try them.
 
Old 06-25-2005, 02:36 AM   #4
Kamikazee
Member
 
Registered: May 2005
Location: Aus
Distribution: SimplyMEPIS 3.3
Posts: 107

Rep: Reputation: 15
Newb Question.

I downloaded the file http://www.l0t3k.net/tools/Loganaly...ce-1.4.2.tar.gz , what do i do with it.. yes it sounds stupid... But i untared it.. then what?
 
Old 06-26-2005, 07:21 AM   #5
ddaas
Member
 
Registered: Oct 2004
Location: Romania
Distribution: Ubuntu server, FreeBsd
Posts: 452

Original Poster
Rep: Reputation: 30
For a new pragram you want to install you have to read:
1) README
2) INSTALL
3)HOWTO

4)Search on GOOGLE
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Iptables Log Analyzer no logs in mysql db! abcampa Linux - Software 1 12-11-2008 02:53 AM
log analyzer MrSandman Linux - Software 2 09-26-2004 01:38 AM
recomend a log analyzer? ziggie216 Linux - Security 1 07-18-2004 05:09 PM
IPtables Log Analyzer from http://www.gege.org/iptables/ brainlego Linux - Software 0 08-11-2003 06:08 AM
Log analyzer? subnet_rx Linux - Security 2 11-06-2001 06:02 AM


All times are GMT -5. The time now is 07:13 PM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration