Re: [Fed-Talk] Syslog, SIEMs, and Laptops
Re: [Fed-Talk] Syslog, SIEMs, and Laptops
- Subject: Re: [Fed-Talk] Syslog, SIEMs, and Laptops
- From: bs <email@hidden>
- Date: Mon, 02 Apr 2012 09:53:16 -0700
On Apr 2, 2012, at 9:25 AM, Todd Heberlein wrote:
> What are people using to aggregate log messages from the Macs in their organization? And in particular, security-relevant logs? And how do you handle it when laptops are connected at the local Starbucks? Do you still send security-relevant log messages (unencrypted?) over the public Wi-Fi?
>
> I want to plug my live analysis directly into an appropriate existing and widely-used log aggregation infrastructure (at least for Macs), but I'm having troubles identifying the right beast to use. Any pointers or suggestions would be appreciated.
Take a look at Splunk <http://www.splunk.com/>.
-BS
_______________________________________________
Do not post admin requests to the list. They will be ignored.
Fed-talk mailing list (email@hidden)
Help/Unsubscribe/Update your Subscription:
This email sent to email@hidden