Web Host Chat - The UK hosting forum
Home QLinks Members Your Profile Register FAQ's Hosts Only Area SMS Alerts Game Servers
Go Back   Web Host Chat > Web Hosting Chat > Business and Technical Advice
Reply
 
LinkBack Thread Tools
Old 18th August 2008   #1 (permalink)
 
andyb28's Avatar
 
Join Date: Dec 2004
Location: Essex
Age: 36
Posts: 1,213
andyb28 is on a distinguished road
Security Log Analyser Tool?

Does anyone know of a good tool that monitors Windows and Linux log files and reports back? (mainly for attempted logins)

I guess I could probably code something, but surely something like this already exists.

TIA
__________________
Andy Booth
Naglotech Ltd
Company No : 5326296 AS35327
andyb28 is offline   Reply With Quote
Old 18th August 2008   #2 (permalink)
 
BurtyB's Avatar
 
Join Date: Apr 2004
Location: Newark, UK
Posts: 864
BurtyB is an unknown quantity at this point
logwatch on Linux if you want to stare at screen after screen of email

ChrisB.
__________________
Chris Burton Othello Technology Systems Ltd AS29527 Company#03894981 VAT#GB-782561410 Tel:0871 277 6875
consultancy domains email forwarding resellers ecommerce colo rackspace ip transit secondary mx/dns dedicated servers backup/DR
* OthelloHosts.net Linux and Windows High-Availability Professional Email / Web / Secure Hosting
* OthelloVPS.net Managed Xen Enterprise Virtual Private Servers and Dedicated Servers
# Currently buying web hosts and domain resellers - www.hostacquisitions.co.uk
Views expressed in this post are my own and not Othello Technology Systems Ltd.
BurtyB is offline   Reply With Quote
Old 18th August 2008   #3 (permalink)
 
Join Date: Aug 2007
Location: Lincoln, UK
Posts: 1,670
freethought is on a distinguished road
If you're looking for something to track failed SSH logins etc. then we use LFD (part of the CSF iptables toolkit) on Linux which can be configured to automatically drop trafic from the source IP. Quite flexible too, you can drop just SSH traffic and set the entries to age out etc.
Pretty sure it can handle FTP, POP3 etc. i you teach it what a failed login looks like in the logs.
Used to use BFD which does pretty much the same thing but isn't maintained any more and lacks some of the options.
__________________
Freethought Internet Limited
Hosting and communications
Freethought Group Limited registered in London No. 5862996. Registered office: The Old Church Hall, 2A Cromwell Street, Lincoln, LN2 5LP.
Xion Internet and Freethought Internet are trading names of Freethought Group Limited.
freethought is offline   Reply With Quote
Old 18th August 2008   #4 (permalink)
Certified Host
 
Join Date: Jan 2004
Location: London
Posts: 488
TDMWeb is on a distinguished road
CSF from ConfigServer Services is very good and does exactly what you want for Linux. Not come across anything similar for Windows.
__________________
Chris at TDMWeb.com
Windows & Linux hosting and fully managed dedicated servers with great customer service!
UK-based but serving the world... (VAT No: 474698684)
TDMWeb is online now   Reply With Quote
Old 19th August 2008   #5 (permalink)
dch
 
Join Date: Nov 2001
Location: Totnes
Posts: 965
dch is on a distinguished road
I think Welcome to the Home of OSSEC will do what you want, it is open source and works with most common OSs

Cheers,
Sean
__________________
» Sean Andrews,
» xoozoo.com ltd - www.xoozoo.com
» Free DNS Report tools - dr.xoozoo.com
» Company no:6482396
dch is offline   Reply With Quote
Old 25th August 2008   #6 (permalink)
Gold Member
 
VooServers's Avatar
 
Join Date: Oct 2005
Location: Medway, UK
Posts: 238
VooServers is on a distinguished road
Microsoft have one but I can't remember the name of it right now. It's pretty cool though as you can wait for a specific event and then make it automatically do the crash on ctrl + scroll lck so it dump's the memory. It's more for troubleshooting specific events but you could also set it up to e-mail when a login event is found. If you search Microsoft you will probably find it anyway but I will check my e-mails when I get a chance.
__________________
Matt Parkinson
Vooservers Limited - Company #05598156 - VAT #871961296
www.vooservers.com
VooServers is offline   Reply With Quote
Old 26th August 2008   #7 (permalink)
 
andyb28's Avatar
 
Join Date: Dec 2004
Location: Essex
Age: 36
Posts: 1,213
andyb28 is on a distinguished road
Is it Operations Manager Matt?
__________________
Andy Booth
Naglotech Ltd
Company No : 5326296 AS35327
andyb28 is offline   Reply With Quote
Old 26th August 2008   #8 (permalink)
Gold Member
 
VooServers's Avatar
 
Join Date: Oct 2005
Location: Medway, UK
Posts: 238
VooServers is on a distinguished road
Quote:
Originally Posted by andyb28 View Post
Is it Operations Manager Matt?
Nope it's a free tool but I believe you have to go through Microsoft Support to get it and then they will e-mail it to you. I have got it on a server somewhere so if I find it I will let you know as the Microsoft link they sent me has expired now.
__________________
Matt Parkinson
Vooservers Limited - Company #05598156 - VAT #871961296
www.vooservers.com
VooServers is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Windows hash tool BurtyB General Chit Chat & Discussion 3 1st April 2008 04:57 PM
Rivals pour scorn on Microsoft security tool [NEWS] Hosting and Tech News 0 7th May 2007 07:31 PM
At last a tool kit for the ladies !! Brent General Chit Chat & Discussion 3 25th December 2006 08:58 PM
[NEWS] Info Security Product Guide Selects Comodo For 2006 ?Hot Company ... - Help Net Security [NEWS] Hosting and Tech News 0 2nd February 2006 12:06 AM

User Information
»REGISTER NOW!
Business and Technical Advice Discussion of issues affecting businesses and any technical queries with all aspects of running a hosting company


Quick forum search
 

Special Hosting Offers

Hot Stuff


Powered by vBulletin® Version 3.8.0
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0