Sorveglianza dei log d'eventi Vigilância dos jornais de acontecimentos (registos) Überwachung der Logs Surveillance des journaux d'événements (logs) Supervisión de registros de eventos

Analysing logs

One of the best ways to detect intrusions is to monitor event logs (sometimes called logs for short).

In general, servers store logs of their activity, and in particular any errors encountered, in files.

Therefore, after a computer attack, it is rare for the hacker to successfully compromise a system on the first try. He/she usually works by trial and error, testing out various requests.

This is why log monitoring can be used to detect suspicious activity. It is particularly important to monitor the logs of security-related software; as well-configured as they may be, they may still be the target of an attack.

Concept of noise

In reality, it is not obvious which alerts are triggered by real attacks by worms and viruses, and which are caused by tools such as vulnerability analysers.

For this reason, most attacks on servers are attacks which are completely unable to compromise the system (such as Microsoft IIS server attacks used on Linux servers with Apache).

They do, however, trigger false alarms, causing what is known as "noise", which makes it harder to focus on real alarms.

Article written 22 July 2005 by Jean-François Pillou.

Last update on Thursday October 16, 2008 02:43:19 PM.This document entitled « Monitoring event logs » from Kioskea (en.kioskea.net) is made available under the Creative Commons license. You can copy, modify copies of this page, under the conditions stipulated by the licence, as this note appears clearly.

Best answers for « Monitoring event logs » in :
Analysing logs Show Analysing logs One of the best ways to detect intrusions is to monitor event logs (sometimes called logs for short). In general, servers store logs of their activity, and in particular any errors encountered, in files. Therefore, after a computer...
Attack detection Show Analysing logs One of the best ways to detect intrusions is to monitor event logs (sometimes called logs for short). In general, servers store logs of their activity, and in particular any errors encountered, in files. Therefore, after a computer...
Expand your Desktop over multiple monitors ShowExpand your Desktop over multiple monitors Hardware Requirements Software Requirements How to proceed If you are using Windows and want to enlarge your current desktop without having to buy another huge screen, this is possible by...
"No Signal" message on Monitor Show“No Signal†message on Monitor When switching on your CPU, you can get the message “No Signal†displayed on your monitor, though the whole system is running. This issue might be due to several factors that you should check...
Connecting to multiple monitors ShowConnecting to multiple monitors Under windows, it is possible to connect multiple monitors enabling simultaneous displays in view to extend the office size and rely on a larger working area. To proceed with this feasibility, it...
Download Network Event Viewer ShowNetwork Event Viewer enables you to fully manage the logs of your network. You can obtain and store in real time all the error messages generated by Windows machines on your private network. Advantage The application takes care of the filter, to...
Download IP Traffic Monitor ShowIP Traffic Monitor monitors all network connections on the computer where it is installed. The program shows you detailed information, such as the remote IP address, host name if available, details of inbound and outbound traffic. Advantage It...
Computer screen or monitor ShowIntroduction to computer monitors A monitor (or screen) is a computer display unit. There are generally said to be two families of monitors: Cathode-ray tube monitors (or CRT for short), which are used with most desktop computers. They are...
Cathode Ray Tube monitor (CRT) ShowCathode ray tube monitor Most monitors (computer screens) use cathode ray tubes (or CRT for short), which are glass vacuum tubes into which an electron gun emits a flow of electrons guided by an electrical field towards a screen covered in small...
Flat monitor ShowFlat-screen monitors Flat-screen monitors (also called FPDs for Flat panel displays) are becoming more and more widespread, as they take up less space and are less heavy than traditional CRT monitors. What's more, the technology used by flat-screen...