[logs] Passive syslog monitoring

ron dilley ron.dilley at gmail.com
Tue Jan 29 15:00:17 PST 2008


List,

I have just posted an update to the Passive Syslog Monitoring Daemon (
http://sourceforge.net/projects/psmd).

Included are tons of bug fixes and a few interesting new features:

* TCP reassembly of syslog over TCP (syslog-ng)
* Logging of lost log data
* TIMEMARK messages to record TZ and clock skew issues (tnx Marcus)

Previous features:

* Passive syslog monitoring (no listening port required)
* Time on wire (with year!), Src & Dst MAC and IP address logging
* MD5/SHA1 hashing of log data archived to disk
* UDP Forwarding of logs with or without forged source IP

Ron
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://www.loganalysis.org/pipermail/loganalysis/attachments/20080129/b810748d/attachment.html


More information about the LogAnalysis mailing list