Koozali.org: home of the SME Server

Firewall log analyser

Andre Courchesne - Consu

Firewall log analyser
« on: January 28, 2002, 07:25:47 AM »
Hi all,

  I saw somewhere here a firewall analyser that would be accessible from a web page that would show actual log analysis of the firewall (thing like post scan attempts,...)

  Can someone point me to this tool?

Andre Courchesne

Luke Drumm

Re: Firewall log analyser
« Reply #1 on: January 29, 2002, 02:31:37 AM »
Snort is probably the best beast for Packet logging (and analysis to some degree) and can be found at www.snort.org .
As for the web interface portion, the snort pages may list something of use. If you use snort to do most of the processing, a simple bit of PHP or Perl should be sufficient to display the log details.

Regards,
Luke