I am looking for a good way to monitor the logs for activity like port scanning or actual hacking. I have been using kiwi to capture the logs for months, but it's not very useful when actually reviewing the pix logs. Does anyone have any recommendations? I have been reviewing Firegen and Stonylakes Reporter but neither is very helpful. I am considering getting an eval of CiscoWorks (pricing around $5000) just to see if that works, but I would like something priced more like $500(plus or minus).
Thanks!
Thanks!