We use syslog-ng for aggregating not only all Pix logs, but also logs from Snort and the Cisco switches and routers. Not sure what kind of alerting fwlogwatch can do, but with the amount of port scans etc that we get on our Pix, I'm not sure I'd want to be alerted on things the pix sees. The IDS are another matter. What kind of alerts can be generated with fwlogwatch? I might consider using something else if it's good. Check out Syslog-ng for a great syslog tool.
|