Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Log Questions

Status
Not open for further replies.
Mar 25, 2004
146
0
0
US
We are testing a new tool to analyze our firewall log we get from kiwi syslog. We had over 100 hits from this ip address yesterday.

Address lookup
canonical name msngames.com.
aliases zone.com
zone.msn.com
sympatico.zone.msn.com

addresses 207.46.203.12


I'm wondering why this is showing up. I'm assuming someone is on here playing but need to track down who it is.

I've been going to centralops.net and doing a domain search to look up all the info. What's the next step someone needs to take that reviews a firewall log? Sorry for all the questions I'm new to this.

Thx
 
One way is to turn on ALL logging on the PIX to the syslogd. BEWARE! You'll be overrun very quickly with messages from the firewall. But if you have and are streaming into a DB, you can parse the messages based on the any criteria you choose. But it takes alot of work.

(FYI, this method also works to monitor internet access and can be used with a report writer like Crystal or MS SQL Reporting Services to make "pretty" reports.)

Happy Hunting.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top