Quote:
Security Logs Analysis for 6/24/2003 at 12:30:04 AM
****************************************************************************
File being analyzed: 2003-06-23.txt. Size 43348442 bytes.
====================================
2003-06-23-Snort.txt 120167 Data Recorded 12:30:14 AM
2003-06-23-Alerts.txt 92541 Data Recorded 12:30:14 AM
2003-06-23-Stealth.txt Zero length Deleted 12:30:19 AM
2003-06-23-Portscan.txt 3326 Data Recorded 12:30:25 AM
2003-06-23-IPv6.txt Zero length Deleted 12:30:30 AM
2003-06-23-Blocked.txt 210250 Data Recorded 12:30:35 AM
2003-06-23-DenyIn.txt 464057 Data Recorded 12:30:41 AM
2003-06-23-DenyOut.txt 121976 Data Recorded 12:30:46 AM
2003-06-23-ICMP.txt 209456 Data Recorded 12:30:52 AM
2003-06-23-FortFirewall.txt 67347 Data Recorded 12:30:57 AM
2003-06-23-IISLogs.txt 1301863 Data Recorded 12:31:02 AM
2003-06-23-IIS404.txt 170586 Data Recorded 12:31:08 AM
2003-06-23-IIS403.txt 1199 Data Recorded 12:31:14 AM
2003-06-23-VPN.txt 32369 Data Recorded 12:31:19 AM
2003-06-23-VPNBadAuth.txt Zero length Deleted 12:31:24 AM
2003-06-23-VPN_SYN.txt Zero length Deleted 12:31:30 AM
2003-06-23-TermServ.txt 1364 Data Recorded 12:31:35 AM
2003-06-23-SSL.txt 123831 Data Recorded 12:31:41 AM
2003-06-23-Lockouts.txt Zero length Deleted 12:31:46 AM
2003-06-23-XXXMain.txt 5542 Data Recorded 12:31:51 AM
2003-06-23-NS2.txt Zero length Deleted 12:31:57 AM
2003-06-23-MAIL.txt 33745 Data Recorded 12:32:02 AM
2003-06-23-XXXPC.txt Zero length Deleted 12:32:08 AM
2003-06-23-XXXBU.txt Zero length Deleted 12:32:13 AM
2003-06-23-CANFPC.txt 487980 Data Recorded 12:32:18 AM
2003-06-23-FORTPC.txt 24648 Data Recorded 12:32:24 AM
2003-06-23-FORTBU.txt 7064 Data Recorded 12:32:29 AM
2003-06-23-XXX-ADMIN.txt 5088 Data Recorded 12:32:35 AM
Analysis Complete at 12:32:35 AM
______________________________________________________________
Begin Archive at 12:32:35 AM
Log Archived to server at 12:33:19 AM
2003-06-23-Alerts.txtmoved at 12:33:20 AM
2003-06-23-Blocked.txtmoved at 12:33:20 AM
2003-06-23-CANFPC.txtmoved at 12:33:20 AM
2003-06-23-XXX-ADMIN.txtmoved at 12:33:20 AM
2003-06-23-DenyIn.txtmoved at 12:33:20 AM
2003-06-23-DenyOut.txtmoved at 12:33:20 AM
2003-06-23-FORTBU.txtmoved at 12:33:20 AM
2003-06-23-FortFirewall.txtmoved at 12:33:20 AM
2003-06-23-FORTPC.txtmoved at 12:33:20 AM
2003-06-23-ICMP.txtmoved at 12:33:20 AM
2003-06-23-IIS403.txtmoved at 12:33:20 AM
2003-06-23-IIS404.txtmoved at 12:33:20 AM
2003-06-23-IISLogs.txtmoved at 12:33:21 AM
2003-06-23-XXXMain.txtmoved at 12:33:21 AM
2003-06-23-MAIL.txtmoved at 12:33:21 AM
2003-06-23-Portscan.txtmoved at 12:33:21 AM
2003-06-23-Snort.txtmoved at 12:33:21 AM
2003-06-23-SSL.txtmoved at 12:33:21 AM
2003-06-23-TermServ.txtmoved at 12:33:21 AM
2003-06-23-VPN.txtmoved at 12:33:21 AM
Email generated at 12:33:21 AM
Report moved at 12:33:27 AM
As you can see most of my work is done by 12:35am......... :D You will note that the script deletes files of zero length and notes that so if someone deleted files to hide their tracks I can see that the file was not zero length and go back to my "secret" copies and regenerate the whole thing.