Great Circle Associates Firewalls
(November 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Parsing CISCO router logs
From: Ed Osterman <eo @ mda . ca>
Date: Tue, 14 Nov 1995 17:24:23 -0800
To: firewalls @ greatcircle . com
Cc: eo @ mda . ca

Hi,
We have just installed a CISCO router and are using its logging
capabilities to notify us via remote syslogging of attempts to use
services and ports that are blocked.

For example, at the end of each access list we explicitly deny all other
port access and request that this be logged. (Note that IP addresses below
are not relevant).


access-list 100 permit icmp 000.000.000.000 255.255.255.255 x.x.x.x 
000.000.255.255 
! This allows logging of access violations
access-list 100 deny   ip  000.000.000.000 255.255.255.255 000.000.000.000 
255.255.255.255 log


Our log file fills with lots of neat info ie:

Nov 14 17:12:06 nb0 5346: %SEC-6-IPACCESSLOGP: list 100 denied tcp 
x.x.x.x(23309) -> x.x.x.x(113), 1 packet

The question is are there any scripts or programs that can parse this
log file and produce some pretty statistics and/or sound alarms/mail when
something is going wrong or there are too many attempts, etc.

Thanks,

-- 
Ed Osterman eo @
 mda .
 ca 	

I guess sometimes there just aren't enough stones to throw.
                                             -Forest Gump





Follow-Ups:
Indexed By Date Previous: Firewalls-Digest V4 #640 -Reply
From: CWSTAFFORD @ deserthosp . org
Next: Re: Parsing CISCO router logs
From: anthony baxter <anthony . baxter @ aaii . oz . au>
Indexed By Thread Previous: Firewalls-Digest V4 #640 -Reply
From: CWSTAFFORD @ deserthosp . org
Next: Re: Parsing CISCO router logs
From: anthony baxter <anthony . baxter @ aaii . oz . au>

Google
 
Search Internet Search www.greatcircle.com