<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Sekiur My Thoughts &#187; Splunk</title>
	<atom:link href="http://blog.sekiur.com/tag/splunk/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.sekiur.com</link>
	<description>VoIP, Mobility, Security, Open Source, Science, Politics, and Technology.</description>
	<lastBuildDate>Wed, 24 Aug 2011 19:46:24 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Finding a Needle in a Haystack</title>
		<link>http://blog.sekiur.com/2009/02/finding-a-needle-in-a-haystack/</link>
		<comments>http://blog.sekiur.com/2009/02/finding-a-needle-in-a-haystack/#comments</comments>
		<pubDate>Thu, 05 Feb 2009 18:21:24 +0000</pubDate>
		<dc:creator>Jose Vicente Ortega</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[AWStats]]></category>
		<category><![CDATA[Log analysis]]></category>
		<category><![CDATA[Site Management]]></category>
		<category><![CDATA[Splunk]]></category>
		<category><![CDATA[Webalizer]]></category>
		<category><![CDATA[WebTrends]]></category>

		<guid isPermaLink="false">http://blog.sekiur.com/?p=730</guid>
		<description><![CDATA[<p><a href="http://blog.sekiur.com/wp-content/uploads/2009/02/needle_in_the_haystack.jpg"></a>I am going to go out on a limb and assert that over 80% of IT shops do not take security seriously and even those who do are not proactive about it.</p> <p>Whenever an anomaly hits the network, system admins and network engineers hit the logs in an attempt to figure what is going [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.sekiur.com/wp-content/uploads/2009/02/needle_in_the_haystack.jpg"><img class="alignleft size-medium wp-image-731" title="needle_in_the_haystack" src="http://blog.sekiur.com/wp-content/uploads/2009/02/needle_in_the_haystack-293x300.jpg" alt="" width="293" height="300" /></a>I am going to go out on a limb and assert that over 80% of IT shops do not take security seriously and even those who do are not proactive about it.</p>
<p>Whenever an anomaly hits the network, system admins and network engineers hit the logs in an attempt to figure what is going on.</p>
<p>Ideally you will have a centralized server running &#8220;<a class="zem_slink" title="Syslog" rel="wikipedia" href="http://en.wikipedia.org/wiki/Syslog">syslog</a>&#8221; gathering logs from all devices on the network that can put out logs.</p>
<p>Unfortunately, unless you&#8217;re &#8220;Neo&#8221; from the movie &#8220;Matrix&#8221; it will almost impossible to make sense, interpret or pick up patterns from the vast amount of data in these logs.</p>
<p>This is were a good Log Analyzer comes in. There are well known log analyzers out there for web traffic, including <a class="zem_slink" title="AWStats" rel="homepage" href="http://awstats.sourceforge.net">AWStats</a>, Analog, WebLogExpert, <a class="zem_slink" title="Webalizer" rel="homepage" href="http://www.webalizer.org/">Webalizer</a> and <a class="zem_slink" title="WebTrends" rel="homepage" href="http://www.webtrends.com">WebTrends</a> but something more comprehensive is needed when it comes to security.</p>
<p>Unmatched as a security <a class="zem_slink" title="Log analysis" rel="wikipedia" href="http://en.wikipedia.org/wiki/Log_analysis">log analysis</a> tool, &#8220;<a class="zem_slink" title="Splunk" rel="homepage" href="http://www.splunk.com/">Splunk</a>&#8221; gathers data from traps, alerts, syslog and snmp as well as imported logs  and lets you graph and search it via a simple web interface. In addition to helping find threats and dangerous trends, it can generate nice reports of your findings.</p>
<p>On the commercial front <a class="zem_slink" title="Sawmill (software)" rel="wikipedia" href="http://en.wikipedia.org/wiki/Sawmill_%28software%29">Sawmill</a> looks like a good product, but I will need to demo and review it.</p>
<p style="text-align: center;"><script type="text/javascript"><!--
google_ad_client = "pub-3340920433757461";
google_ui_features = "rc:10";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text_image";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://arnoldit.com/wordpress/2008/10/05/splunk-new-search-engine/">Splunk: Log File Search Engine</a> (arnoldit.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.macworld.com/article/135710/2008/10/visistat6.html?lsrc=rss_main">Review: VisiStat 6.0</a> (macworld.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.xaprb.com/blog/2008/12/01/maatkit-version-2582-released/">Maatkit version 2582 released</a> (xaprb.com)</li>
<li class="zemanta-article-ul-li"><a href="http://webtribution.com/2008/10/07/web-success-the-traffic-conversion-retention-tcr-lifecycle-%25e2%2580%2593-part-i/">Web Success: The Traffic, Conversion, Retention (TCR) Lifecycle &#8211; Part I</a> (webtribution.com)</li>
<li class="zemanta-article-ul-li"><a href="http://seomashup.blogspot.com/2008/12/google-real-estate-seo-rankings-now.html">Google Real Estate SEO Rankings Now Skyrocket and Sends Reports with WebsTarget and VisiStat Joint Venture</a> (seomashup.blogspot.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/231ded40-086c-4141-b54d-b87061686c62/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=231ded40-086c-4141-b54d-b87061686c62" alt="Reblog this post [with Zemanta]" /></a></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.sekiur.com/2009/02/finding-a-needle-in-a-haystack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

