Web Host Chat
Bringing Hosts & Customers together since 2001
Home QLinks Members Your Profile Register FAQ's Hosts Only Area SMS Alerts Advertising
User Information
»REGISTER NOW!

Go Back   Web Host Chat > Web Hosting Chat > Business and Technical Advice
Reply
 
LinkBack Thread Tools
Old 18th August 2008   #1 (permalink)
I am Staff at
Naglotech
About My Company!


Basic Host
andyb28's Avatar
Join Date: Dec 2004
Location: Essex
Age: 35
Posts: 1,180
andyb28 is on a distinguished road
Security Log Analyser Tool?

Does anyone know of a good tool that monitors Windows and Linux log files and reports back? (mainly for attempted logins)

I guess I could probably code something, but surely something like this already exists.

TIA
__________________
Andy Booth

Naglotech Ltd Webhosting, Colocation, Consultancy
Cybernetic-Servers Game Servers, Dedicated Servers

Company No : 5326296
AS35327
__________________
Web Host - VIP Member
andyb28 is online now   Reply With Quote
Old 18th August 2008   #2 (permalink)
I am Staff at
8086 Limited
About My Company!

Certified Host
BurtyB's Avatar
Join Date: Apr 2004
Location: Newark, UK
Posts: 795
BurtyB is an unknown quantity at this point
logwatch on Linux if you want to stare at screen after screen of email

ChrisB.
__________________
Chris Burton
8086 Limited (Company No.: 06336617 VAT No.: 920 5102 75)
Ever wanted to know who uses a DNS or MX server ? with DNS History you can find out.
__________________
Web Host - Certified Member
BurtyB is offline   Reply With Quote
Old 18th August 2008   #3 (permalink)
Join Date: Aug 2007
Location: Lincoln, UK
Posts: 489
freethought is on a distinguished road
If you're looking for something to track failed SSH logins etc. then we use LFD (part of the CSF iptables toolkit) on Linux which can be configured to automatically drop trafic from the source IP. Quite flexible too, you can drop just SSH traffic and set the entries to age out etc.
Pretty sure it can handle FTP, POP3 etc. i you teach it what a failed login looks like in the logs.
Used to use BFD which does pretty much the same thing but isn't maintained any more and lacks some of the options.
__________________
Freethought Group Limited
Hosting and communications
Freethought Group Limited registered in London No. 5862996. Registered office: The Old Church Hall, 2A Cromwell Street, Lincoln, LN2 5LP.
Xion Internet and Freethought Internet are trading names of Freethought Group Limited.
__________________
Web Host - Certified Member
freethought is online now   Reply With Quote
Old 18th August 2008   #4 (permalink)
I am Staff at
TDMWeb
About My Company!

Certified Host
Join Date: Jan 2004
Location: London
Posts: 414
TDMWeb is on a distinguished road
CSF from ConfigServer Services is very good and does exactly what you want for Linux. Not come across anything similar for Windows.
__________________
Chris at TDMWeb.com
Windows & Linux hosting and fully managed dedicated servers with great customer service!
UK-based but serving the world... (VAT No: 474698684)
__________________
Web Host - Certified Member
TDMWeb is offline   Reply With Quote
Old 19th August 2008   #5 (permalink)
I am Staff at
xoozoo Ltd
About My Company!

Certified Host
Join Date: Nov 2001
Location: Totnes
Posts: 858
dch is on a distinguished road
I think Welcome to the Home of OSSEC will do what you want, it is open source and works with most common OSs

Cheers,
Sean
__________________
» Sean Andrews,
» xoozoo.com ltd - www.xoozoo.com
» Free DNS Report tools - dr.xoozoo.com
» Company no:6482396
__________________
Web Host - Certified Member
dch is offline   Reply With Quote
Old 25th August 2008   #6 (permalink)
I am Staff at
Vooservers
About My Company!

Certified Host
VooServers's Avatar
Join Date: Oct 2005
Location: Medway, UK
Posts: 238
VooServers is on a distinguished road
Microsoft have one but I can't remember the name of it right now. It's pretty cool though as you can wait for a specific event and then make it automatically do the crash on ctrl + scroll lck so it dump's the memory. It's more for troubleshooting specific events but you could also set it up to e-mail when a login event is found. If you search Microsoft you will probably find it anyway but I will check my e-mails when I get a chance.
__________________
Matt Parkinson
Vooservers Limited - Company #05598156 - VAT #871961296
www.vooservers.com
__________________
Web Host - Certified Member
VooServers is offline   Reply With Quote
Old 26th August 2008   #7 (permalink)
I am Staff at
Naglotech
About My Company!


Basic Host
andyb28's Avatar
Join Date: Dec 2004
Location: Essex
Age: 35
Posts: 1,180
andyb28 is on a distinguished road
Is it Operations Manager Matt?
__________________
Andy Booth

Naglotech Ltd Webhosting, Colocation, Consultancy
Cybernetic-Servers Game Servers, Dedicated Servers

Company No : 5326296
AS35327
__________________
Web Host - VIP Member
andyb28 is online now   Reply With Quote
Old 26th August 2008   #8 (permalink)
I am Staff at
Vooservers
About My Company!

Certified Host
VooServers's Avatar
Join Date: Oct 2005
Location: Medway, UK
Posts: 238
VooServers is on a distinguished road
Quote:
Originally Posted by andyb28 View Post
Is it Operations Manager Matt?
Nope it's a free tool but I believe you have to go through Microsoft Support to get it and then they will e-mail it to you. I have got it on a server somewhere so if I find it I will let you know as the Microsoft link they sent me has expired now.
__________________
Matt Parkinson
Vooservers Limited - Company #05598156 - VAT #871961296
www.vooservers.com
__________________
Web Host - Certified Member
VooServers is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Windows hash tool BurtyB General Chit Chat & Discussion 3 1st April 2008 04:57 PM
Rivals pour scorn on Microsoft security tool [NEWS] Hosting and Tech News 0 7th May 2007 07:31 PM
At last a tool kit for the ladies !! Brent General Chit Chat & Discussion 3 25th December 2006 09:58 PM
[NEWS] Info Security Product Guide Selects Comodo For 2006 ?Hot Company ... - Help Net Security [NEWS] Hosting and Tech News 0 2nd February 2006 01:06 AM


Some great companies!


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0