Cash is the name of the game here. If you have enough horsepower and enough cash, pump your syslog dump into a SIM (Security Information Manager) product such as NeuSecure by http://www.Guarded.net.
The sky is the limit as to what you can do with the data when a solution like this gets its teeth in your data.
If you're broke, then PERL and simple piped linux commands such as cat <filename> | grep 'something to find' will do the trick as long as you are aware of how to write expressions in a way that the shell wont interpret them.
Anyway, just another 2 cents...




Reply With Quote