Answer the question
In order to leave comments, you need to log in
Centralized syslog server, and further analysis of the collected data?
Hello, in general,
there are no problems with raising the centralized log server.
It would be desirable to learn than then to disassemble to systematize these broad gulls, and to send notifications.
I looked at OSSIM but it's too heavy.
I would be grateful if anyone could share their experience
Thank you
Answer the question
In order to leave comments, you need to log in
ArcSight Logger, Q1 Logger, LogLogic, Splunk, etc. Thousands of them. Paid mostly, of course.
Here is the last article about logs and sending notifications
https://habrahabr.ru/post/345968/
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question