[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
events
On Fri, Sep 30, 2011 at 2:44 PM, Ukpong Ukpong <ukpong.ukpong at gmail.com> wrote:
> Have you tried qradar? It's rather good
I've used Splunk and QRadar; both are available as free VMware
appliances with limitations on log volume, sufficient for testing. Or
if you're mostly looking at webserver/proxy/firewall logs, Sawmill is
worth checking out.
I've also been looking into using Lancope's replicator to take in
syslog UDP and send copies to multiple loggers, since some appliances
only support a single syslog destination.
Kevin
- References:
- events
- From: harbor235 at gmail.com (harbor235)
- events
- From: pfunix at gmail.com (Beavis)
- events
- From: brandon.kim at brandontek.com (Brandon Kim)
- events
- From: mloftis at wgops.com (Michael Loftis)
- events
- From: brandon.kim at brandontek.com (Brandon Kim)
- events
- From: jason at lixfeld.ca (Jason Lixfeld)
- events
- From: ukpong.ukpong at gmail.com (Ukpong Ukpong)