Hi, I cannot get lire 2.01 (installed from the
dvd rpms of Mandriva 2005 LE) to create any report.
In, brief, does anybody use lire and got it to work straight of the rpms that came with the distro?
My goal is to output an analysis of the hits to the firewall (shorewall), and a report of all oddities and warning in /var/log/syslog, including snort warnings.
Lire does not spit any error messages,
and the dlf store does increase in size
everytime the crontab lr_cron hourly /home/my_store runs. I cannot find any output report (using locate and the name of the file report name template given in lire; I tried txt and html formats)
I have installed DBD::SQLite2.
I have run as well lr_run as root, on the command line , got the dlf to increase in size, but never got any warning that I should not run lire as root (however I believe it is supposed to give this kind of message). So this is weird.
I have setup a stream, a report, and selected a type of report as firewall.
Should my_store be in /var/lib/lire/my_store ?
I tried for the file name template of the report just myreport and /home/myreport. I did not try email reporting because the PC is not really setup for sending email automatically (no postfix, nor sendmail configured anyway, if this is what would be needed. Beyonfd me for now. Am happy with kmail).
(Lire website) http://logreport.org/lire/lire201.php
It is for a desktop use. I have no webserver.
I manage to get fwlogwatch to work otherwise, and snortsnarf.
I am not keen to install mysql and apache(I see these as an overkill at this stage).
As a side question, for a desktop log analyser, what would you suggest? I have looked at all these, but they look to complicated for a desktop installation (maybe I am getting it wrong).
Webmin: Webalizer Logfile Analysis
"Generate reports from webserver, proxy server and FTP log files"
Does it do simpler thing like creating report just from /var/log/syslog?
Swatch: got to write my own regexp.
There was a ready made swatch conf files for mandrake rpms.
Swatch will do to catch keywords like error, warnings...
I think I will use it.
Sounds like a hammer to crack nuts.
What confuses me is that I read somewhere that I needed a webserver (apache), or it sounds like most log analalyser need apache. Do I understand this wrongly? Is apache used to format the reports?
PS: looking also at http://tud.at/programm/fwanalog/
But not so sure yet it is what I need