Welcome! Log In Create A New Profile

Advanced

Re: loggint through syslog

merlin corey
December 17, 2009 08:04PM
On Thu, Dec 17, 2009 at 4:41 PM, Ryan Malayter <malayter@gmail.com> wrote:
> On Thursday, December 17, 2009, merlin corey <merlincorey@dc949.org> wrote:
>> Many log analyzers work fine with multiple files from multiple
>> sources, at least I know analog does.  Failing that, you could write a
>> script to aggregate the logs...
>
> I think a more important use case for syslog is enabling
> tamper-resistant logs to another system. Syslog over IPSec to an
> unrelated system is a lot more confidence inspiring to security folks
> than a local text file that can be modified after a breach.
>
>
> --
> RPM
>
> _______________________________________________
> nginx mailing list
> nginx@nginx.org
> http://nginx.org/mailman/listinfo/nginx
>

If you want to wear that security blanket, go ahead.

If you are worried about the integrity of your logfiles, you should
implement some kind of integrity checking on every important point.
This means that even if you do push things over your favorite secure
protocol to another system you'll want to do some kind of integrity
checking there because someone could break in and tamper with the data
on the "secure" system.

Security folks know that everything breaks, so they plan for and
monitor breakages.

What's the plan for when the syslog server goes down? No logs at all then?

-- Merlin

_______________________________________________
nginx mailing list
nginx@nginx.org
http://nginx.org/mailman/listinfo/nginx
Subject Author Posted

loggint through syslog

Gabri Mate December 16, 2009 04:58PM

Re: loggint through syslog

merlin corey December 17, 2009 05:30PM

Re: loggint through syslog

Ryan Malayter December 17, 2009 07:46PM

Re: loggint through syslog

merlin corey December 17, 2009 08:04PM

Re: loggint through syslog

Ryan Malayter December 18, 2009 12:38AM

Re: loggint through syslog

merlin corey December 18, 2009 08:18PM

Re: loggint through syslog

Ryan Malayter December 19, 2009 10:08PM

Re: loggint through syslog

merlin corey December 21, 2009 08:24PM

Re: loggint through syslog

Vinay Y s December 20, 2009 11:54AM

Re: loggint through syslog

Peter Leonov December 20, 2009 05:58PM

Re: loggint through syslog

mike December 20, 2009 06:02PM

Re: loggint through syslog

Kingsley Foreman December 20, 2009 06:08PM

Re: loggint through syslog

mike December 20, 2009 06:14PM

Re: loggint through syslog

Ryan Malayter December 24, 2009 01:04AM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 127
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready