Which log analyser do you use ?
Just trying to find a good analyser that reports unusual items in your logs. I tried out logcheck and it seemed nice but it keeps borking with my /tmp after about a day or 2 and I have to apt-get --reinstall it. Its error is that a temp file it makes in /tmp no longer exits.
So anyway I have looked around and see epylog and logwatch might be good.... swatch which is more of real-time alert daemon which could be useful too and lire which I think I might try out now.
Just curious as to what LQ users use to monitor their server's for unusual activity
Thanks for reading
|