<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>chrisbrenton.org &#187; Logging</title>
	<atom:link href="http://www.chrisbrenton.org/category/security/logging/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.chrisbrenton.org</link>
	<description>Your source for invisible security bug spray</description>
	<lastBuildDate>Mon, 22 Aug 2011 01:04:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Combining Logwatch and OSSEC – Part 4</title>
		<link>http://www.chrisbrenton.org/2010/02/combining-logwatch-and-ossec-%e2%80%93-part-4/</link>
		<comments>http://www.chrisbrenton.org/2010/02/combining-logwatch-and-ossec-%e2%80%93-part-4/#comments</comments>
		<pubDate>Thu, 18 Feb 2010 20:05:52 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[3-err]]></category>
		<category><![CDATA[Logging]]></category>

		<guid isPermaLink="false">http://www.chrisbrenton.org/?p=811</guid>
		<description><![CDATA[In my last post we installed Logwatch as well as OSSEC. It is now time to get Logwatch and OSSEC playing together in the same sandbox. In this post I’ll discuss how to get Logwatch to summarize the information being generated by OSSEC. Deployment Options We have two paths we can follow to set this [...]]]></description>
		<wfw:commentRss>http://www.chrisbrenton.org/2010/02/combining-logwatch-and-ossec-%e2%80%93-part-4/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Combining Logwatch and OSSEC – Part 3</title>
		<link>http://www.chrisbrenton.org/2010/02/combining-logwatch-and-ossec-%e2%80%93-part-3/</link>
		<comments>http://www.chrisbrenton.org/2010/02/combining-logwatch-and-ossec-%e2%80%93-part-3/#comments</comments>
		<pubDate>Wed, 17 Feb 2010 20:46:00 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[3-err]]></category>
		<category><![CDATA[Logging]]></category>

		<guid isPermaLink="false">http://www.chrisbrenton.org/?p=807</guid>
		<description><![CDATA[In my last two posts I discussed Logwatch and OSSEC, as well as how they can be leverage to augment your security posture. In this installment I’ll discuss how to install both of these tools. Installing Logwatch Logwatch is pretty easy to install. In fact, it is installed by default on many Linux distributions so [...]]]></description>
		<wfw:commentRss>http://www.chrisbrenton.org/2010/02/combining-logwatch-and-ossec-%e2%80%93-part-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Combining Logwatch and OSSEC – Part 2</title>
		<link>http://www.chrisbrenton.org/2010/02/combining-logwatch-and-ossec-%e2%80%93-part-2/</link>
		<comments>http://www.chrisbrenton.org/2010/02/combining-logwatch-and-ossec-%e2%80%93-part-2/#comments</comments>
		<pubDate>Tue, 16 Feb 2010 16:45:07 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[3-err]]></category>
		<category><![CDATA[Logging]]></category>

		<guid isPermaLink="false">http://www.chrisbrenton.org/?p=803</guid>
		<description><![CDATA[In my last post I described how Logwatch could be used to simplify the log review process. In this post we’ll look at OSSEC and what it brings to the table. What Is OSSEC? OSSEC, short for “Open Source SECurity”, is a host based intrusion detection system (HIDS). In other words, it is designed to [...]]]></description>
		<wfw:commentRss>http://www.chrisbrenton.org/2010/02/combining-logwatch-and-ossec-%e2%80%93-part-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Combining Logwatch and OSSEC</title>
		<link>http://www.chrisbrenton.org/2010/02/combining-logwatch-and-ossec/</link>
		<comments>http://www.chrisbrenton.org/2010/02/combining-logwatch-and-ossec/#comments</comments>
		<pubDate>Mon, 15 Feb 2010 19:39:13 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[3-err]]></category>
		<category><![CDATA[Logging]]></category>

		<guid isPermaLink="false">http://www.chrisbrenton.org/?p=797</guid>
		<description><![CDATA[I recently had a student ask me a question regarding the integration of Logwatch with OSSEC. I felt like this was a complex and yet cool enough idea that it warranted a series of posts to cover it in full. So over the next few days I’ll talk about each of these tools, how to [...]]]></description>
		<wfw:commentRss>http://www.chrisbrenton.org/2010/02/combining-logwatch-and-ossec/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Setting Up A Security Information Management System-Part 6</title>
		<link>http://www.chrisbrenton.org/2009/08/setting-up-a-security-information-management-system-part-6/</link>
		<comments>http://www.chrisbrenton.org/2009/08/setting-up-a-security-information-management-system-part-6/#comments</comments>
		<pubDate>Thu, 20 Aug 2009 09:56:18 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[3-err]]></category>
		<category><![CDATA[Logging]]></category>
		<category><![CDATA[log management]]></category>
		<category><![CDATA[security information management]]></category>
		<category><![CDATA[SIM]]></category>

		<guid isPermaLink="false">http://www.chrisbrenton.org/?p=450</guid>
		<description><![CDATA[So far in this series we have covered: Defining a scope and focus for your SIM Importance of building instead of buying your first system Architecture and capacity planning Recommended phases of deployment Selecting a centralized logging server platform How to accept remote log entries Facility, severity and priority How to sort log messages Configuring [...]]]></description>
		<wfw:commentRss>http://www.chrisbrenton.org/2009/08/setting-up-a-security-information-management-system-part-6/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Setting Up A Security Information Management System-Part5</title>
		<link>http://www.chrisbrenton.org/2009/08/setting-up-a-security-information-management-system-part5/</link>
		<comments>http://www.chrisbrenton.org/2009/08/setting-up-a-security-information-management-system-part5/#comments</comments>
		<pubDate>Fri, 14 Aug 2009 09:44:29 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[3-err]]></category>
		<category><![CDATA[Logging]]></category>
		<category><![CDATA[log management]]></category>
		<category><![CDATA[security information management]]></category>
		<category><![CDATA[SIM]]></category>

		<guid isPermaLink="false">http://www.chrisbrenton.org/?p=412</guid>
		<description><![CDATA[In my last post I discussed how a logging server uses a message’s priority value to sort incoming log messages. In this installment I’ll talk about testing connectivity, as well as how to get various gear on the wire to submit their log entries to a centralized server. Requirements In order for a system to [...]]]></description>
		<wfw:commentRss>http://www.chrisbrenton.org/2009/08/setting-up-a-security-information-management-system-part5/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Setting Up A Security Information Management System-Part4</title>
		<link>http://www.chrisbrenton.org/2009/08/setting-up-a-security-information-management-system-part4/</link>
		<comments>http://www.chrisbrenton.org/2009/08/setting-up-a-security-information-management-system-part4/#comments</comments>
		<pubDate>Wed, 12 Aug 2009 10:01:48 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[3-err]]></category>
		<category><![CDATA[Logging]]></category>
		<category><![CDATA[log management]]></category>
		<category><![CDATA[security information management]]></category>
		<category><![CDATA[SIM]]></category>

		<guid isPermaLink="false">http://www.chrisbrenton.org/?p=390</guid>
		<description><![CDATA[In the last post I talked about how to setup a logging server that will accept remote log entries. In this installment I’ll talk about how to sort log entries into specific files. Facility, severity and priority Let’s talk about how logging servers figure out which file to store a log entry in when it [...]]]></description>
		<wfw:commentRss>http://www.chrisbrenton.org/2009/08/setting-up-a-security-information-management-system-part4/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Setting Up A Security Information Management System-Part3</title>
		<link>http://www.chrisbrenton.org/2009/08/setting-up-a-security-information-management-system-part3/</link>
		<comments>http://www.chrisbrenton.org/2009/08/setting-up-a-security-information-management-system-part3/#comments</comments>
		<pubDate>Tue, 11 Aug 2009 10:01:08 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[3-err]]></category>
		<category><![CDATA[Logging]]></category>
		<category><![CDATA[log management]]></category>
		<category><![CDATA[security information management]]></category>
		<category><![CDATA[SIM]]></category>

		<guid isPermaLink="false">http://www.chrisbrenton.org/?p=376</guid>
		<description><![CDATA[In the last post I covered some of the architecture concerns with rolling out a centralized security information system. In this post I’ll cover deploying a basic log server, and verifying that it is ready to accept log entries. Selecting a logging server The first thing we need to do is select a platform for [...]]]></description>
		<wfw:commentRss>http://www.chrisbrenton.org/2009/08/setting-up-a-security-information-management-system-part3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Setting Up A Security Information Management System-Part2</title>
		<link>http://www.chrisbrenton.org/2009/08/setting-up-a-security-information-management-system-part2/</link>
		<comments>http://www.chrisbrenton.org/2009/08/setting-up-a-security-information-management-system-part2/#comments</comments>
		<pubDate>Mon, 10 Aug 2009 17:15:43 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[3-err]]></category>
		<category><![CDATA[Logging]]></category>
		<category><![CDATA[log management]]></category>
		<category><![CDATA[security information management]]></category>
		<category><![CDATA[SIM]]></category>

		<guid isPermaLink="false">http://www.chrisbrenton.org/?p=371</guid>
		<description><![CDATA[In my last post we discussed defining your goals for a Security Information Management (SIM) system. In this post we’ll talk about architecture concerns as well as capacity planning. Network communications The goal will be to have one or more SIM servers that will collect log entries from other systems. This will obviously have an [...]]]></description>
		<wfw:commentRss>http://www.chrisbrenton.org/2009/08/setting-up-a-security-information-management-system-part2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Setting Up A Security Information Management (SIM) System – Part 1</title>
		<link>http://www.chrisbrenton.org/2009/08/setting-up-a-security-information-management-system-sim-%e2%80%93-part-1/</link>
		<comments>http://www.chrisbrenton.org/2009/08/setting-up-a-security-information-management-system-sim-%e2%80%93-part-1/#comments</comments>
		<pubDate>Sat, 08 Aug 2009 13:46:21 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[3-err]]></category>
		<category><![CDATA[Logging]]></category>
		<category><![CDATA[log management]]></category>
		<category><![CDATA[security information management]]></category>
		<category><![CDATA[SIM]]></category>

		<guid isPermaLink="false">http://www.chrisbrenton.org/?p=362</guid>
		<description><![CDATA[I get a lot of logging related questions. So much so that I decided to do a series on how to deploy log management. There are some excellent logging resources on the Internet, but they are fragmented in scope and/or vendor specific (usually written by the vendors). I wanted to create something vendor neutral that holds your hand through the entire process of deploying a log management solution.
]]></description>
		<wfw:commentRss>http://www.chrisbrenton.org/2009/08/setting-up-a-security-information-management-system-sim-%e2%80%93-part-1/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>

