The most trusted source for computer security training, certification and research.



select a course
San Jose, CA - April 23 - 25, 2007
Global Information Assurance Certification

SANS is a great place to enhance your technical and hands on skills and tools. I thoroughly recommend it.
-Aaron Waugh, Datacom NZ Ltd.


Additional Course Offerings: Additional courses are available in San Jose on April 25th. Please visit the WhatWorks in Log Management Summit 2007 page for more information.

SPECIAL

Building a Log Analysis System from Open Source Tools

Wednesday, April 25, 2007 : 1pm - 4pm
Chris Brenton, SANS Faculty Fellow
3 CPE Credits Per Day

While commercial applications can provide a simplified path to deploying a centralized log analysis system, they can be limiting. Depending on your infrastructure design and choice of systems, it may be difficult to find the flexibility required to match your specific needs. One possible option to resolving this problem is to build your own modular system using open source tools.

This half day course is a nuts and bolts how-to on building your own log analysis system. Students attending this course will learn how to create a logging system that gives them better visibility of the events occurring on their network. In addition, the system will provide real time alerting while reducing the amount of administration time required to monitor events.

  • Topics include:
    • Strengths and weaknesses of an open source solution
    • When to go commercial and when to build your own
    • Goals of centralized logging and alerting
    • Components of a log analysis system
    • Choosing a logging standard
    • Logging server placement & design considerations
    • Scale considerations
    • Validating log receipt
    • Should I secure the data stream?
    • The importance of time sync
    • Centralized log server build up
    • Configuring end devices (Windows, UNIX, Cisco IOS, etc.)
    • Creating an audit trail
    • Choosing a log file format and management scheme
    • Breaking out from time linear log reviews
    • Tools to assist in log file review
    • What to look for Performing real time alerting

SANS never fails to provide top level training that is worth every penny.
-Tyler Hudak, Yellow Roadway Tech