Open source and free log analysis and log management tools.

Maintained by Dr. Anton Chuvakin
Version 1 created 3/3/2010
Version 1.1 updated 4/15/2010
Version 1.2 updated 10/1/2010
Version 1.3 updated 3/3/2011

This page lists a few popular free open-source log management and log analysis tools. The page is a supplement to "Critical Log Review Checklist for Security Incidents" that can be found here or as PDF or DOC (feel free to modify it for your own purposes or for internal distribution - but please keep the attribution).
The log cheat sheet presents a checklist for reviewing critical system,
network and security logs when responding to a security incident. It
can also be used for routine periodic log review. It was authored by Dr. Anton Chuvakin and Lenny Zeltser.

The open source log management tools are:

  1. OSSEC (ossec.net
    an
    open source tool for  analysis of real-time log data from Unix systems,
    Windows servers and network devices. It includes a set of useful
    default alerting rules as well as a web-based graphical user interface.
    This is THE tool to use, if you are starting up your log review program.
    It even has a book written about it.
  2. Snare agent
    (intersectalliance.com/projects/index.html) and ProjectLasso remote collector (sourceforge.net/projects/lassolog)
    are used to convert Windows Event Logs into syslog, a key component of any log management infrastructure today (at
    least until Visa/W7 log aggregation tools become mainstream).
  3. syslog-ng (balabit.com/network-security/syslog-ng/) is a replacement and improvement of classic syslog service - it also has a Windows version that can be used the same way as Snare
  4. rsyslog (rsyslog.com)
    is another notable replacement and improvement of syslog service that
    uses traditional (rather than ng-style) format for syslog.conf
    configuration files. No Windows version, but it has an associated
    front-end called phpLogCon
  5. Among the somewhat dated tools, Logwatch (logwatch.org), Lire (logreport.org) and LogSurfer (crypt.gen.nz/logsurfer) can all be used to summarize logs into readable reports.
  6. sec (simple-evcorr.sourceforge.net) can be used for correlating logs, even though most people will likely find OSSEC correlation a bit easier to use
  7. LogHound (ristov.users.sourceforge.net/loghound) and slct (ristov.users.sourceforge.net/slct) are more "research-grade" tools, that are still very useful for going thru a large pool of barely-structured log data.
  8. Log2timeline (log2timeline.net/) is a useful tool for investigative review of logs; it can create a timeline view out of raw log data.
  9. LogZilla (aka php-syslog-ng) (code.google.com/p/php-syslog-ng)
    is a simple PHP-based visual front-end for a syslog server to do searches, reports, etc

The next list is "an honorable mentions" list which inlcudes logging tools that don't quite fit the definition above:

  • Splunk is neither free nor
    open source, but is has a free version usable for searching up to 500MB
    of log data per day - think of it as a smart search engine for logs.
    Splunk includes a tool to extracting parameters out of log data
  • Offering both fast index searches and parsed data reports, Novell Sentinel Log Manager 25
    is not open source, but can be used for free forever as long as your
    log data volume does not exceed 25 log messages/second (25 EPS). Unlike
    splunk above, it includes log data parsing for select log formats and
    thus can be used for running reports out of the box, not just searching
  • Q1Labs is also neither free nor open source, but is has a free version usable for managing up to 50EPS (roughly 2GB/day). It can be downloaded as a virtual appliance
  • OSSIM  is not just for logs and also includes OSSEC; it  is an
    open source SIEM tool and can be used much the same way as commercial
    Security Information and Event Management tools are used (SIEM use cases)
  • Microsoft Log Parser
    is a handy free tool to cut thru various Windows logs, not just Windows
    Event Logs. A somewhat similar tool for Windows Event log analysis is
    Mandiant Highlighter (mandiant.com/products/free_software/highlighter)
  • Sguil is not a log analysis tools, but a  network security monitoring (NSM) tool, but it uses logs in its analysis.
  • Loggly now offers free developer accounts (at loggly.com/signup)
    for their cloud log management service. The volume limitation is
    200MB/day and retention time limiation is 7 days. If you'd like to
    collect and search your logs without running any software, this is for
    you.

For a list of commercial log management tools go to Security Scoreboard site. A few of the commercial tools offer free trials for
up to 30 days or longer.

Back to Security Warrior Consulting by Dr. Anton Chuvakin.

Modified: 08-Mar-2011

Open source and free log analysis and log management tools.的更多相关文章

  1. openstack-lanch an instance and nova compute log analysis

    1. how to launch an instance: [root@localhost ~(keystone_admin)]# nova flavor-list+----+-----------+ ...

  2. android log机制——输出log【转】

    转自:http://blog.csdn.net/tdstds/article/details/19084327 目录(?)[-] 在android Java code中输出log Logprintln ...

  3. 7.5 Point-in-Time (Incremental) Recovery Using the Binary Log 使用binay log 基于时间点恢复

    7.5 Point-in-Time (Incremental) Recovery Using the Binary Log 使用binay log 基于时间点恢复 7.5.1 Point-in-Tim ...

  4. Oracle之 等待事件log file sync + log file parallel write (awr优化)

    这是3月份某客户的情况,原因是server硬件故障后进行更换之后,业务翻译偶尔出现提交缓慢的情况.我们先来看下awr的情况. 我们能够看到,该系统的load profile信息事实上并不高,每秒才21 ...

  5. aliyun 日志服务(Log Service,Log)是针对日志场景的一站式服务

    日志服务(Log Service,Log)是针对日志场景的一站式服务,在阿里巴巴集团内部被广泛使用.用户无需开发就能快捷完成日志生命周期中采集.消费.投递以及查询功能. 日志服务当前提供如下功能 日志 ...

  6. 日志:Redo Log 和 Undo Log

    本篇文章主要介绍 Redo Log 和 Undo Log: 利用 Redo Log 和 Undo Log 实现本地事务的原子性.持久性 Redo Log 的写回策略 Redo Log Buffer 的 ...

  7. [转]undo log与redo log原理分析

    数据库通常借助日志来实现事务,常见的有undo log.redo log,undo/redo log都能保证事务特性,这里主要是原子性和持久性,即事务相关的操作,要么全做,要么不做,并且修改的数据能得 ...

  8. 使用华为U8860测试时出现“Unable to open log device '/dev/log/main': No such file or directory”

    这是因为华为默认禁掉了log输出, 解决办法: 拨号: *#*#2846579#*#* 会显示工程菜单, Go to "ProjectMenu" -> "Backg ...

  9. Oracle 11g的Redo Log和Archive Log的分析方法

    自Oracle 11g起,无需设置UTL_FILE_DIR就可以使用LOGMNR对本地数据库的日志进行分析,以下是使用LOGMNR的DICT_FROM_ONLINE_CATALOG分析REDO和归档日 ...

随机推荐

  1. Facebook发布C++ HTTP框架Proxygen

    Facebook 宣布发布C++ HTTP 框架 Proxygen,其中包括了一个 HTTP server.Proxygen 是 oxygen 的谐音,支持 SPDY/3 和 SPDY/3.1,未来还 ...

  2. 鼠标聚焦到Text输入框时,按回车键刷新页面原因及解决方法

    前提 一个form中只有一个输入框,当输入框获取焦点后,点击回车,导致整个页面都刷新,问题解决办法. 1.处理form  在form中添加事件 <form onsubmit="retu ...

  3. Hive进阶(下)

    Hive进阶(下) Hive进阶(下) Hive的表连接 等值连接 查询员工信息:员工号.姓名.月薪.部门名称 1.select e.empno,e.ename,e.sal,d.dname2.from ...

  4. IO-02

    /** 2 *A2-IO-02. 整数四则运算(10) 3 *C语言实现 4 *测试已通过 5 */ #include "stdio.h" #include "stdli ...

  5. Struts2的Stack Context和ValueStack

    1.提到Struts2的传值功能时,经常会见到Stack Context和ValueStack等概念,那么它们到底是什么,有什么作用呢. ValueStack(值栈):Struts2将OGNL上下文设 ...

  6. iOS多线程系列(2)

    前面了iOS的NSThread方法来实现多线程,这篇就简单的讲讲NSOperation和NSOperationQueue. NSOperation是一个抽象类,定义一个要执行的任务.NSOperati ...

  7. 帮助中心 7D-我的私家设计师 设计师品牌服饰集成网 7D服装定制!

    帮助中心 7D-我的私家设计师 设计师品牌服饰集成网 7D服装定制! 关于我们

  8. 【数据库】SQL优化方法汇总

    最近在研究SQL语句的优化问题. 下面是从网上搜集的,有的地方有点老了,可是还是有很多可以借鉴的地方的. 如何加快查询速度? 1.升级硬件. 2.根据查询条件,建立索引,优化索引.优化访问方式,限制结 ...

  9. 20141112 WinForm子窗口标签页

    (一)标签页 先看看效果: 代码: public partial class 标签页 : Form { string s = ""; public 标签页() { Initiali ...

  10. OCP-1Z0-053-V12.02-512题 【转】

    http://blog.csdn.net/gisinfo/article/details/8159875 1.Which two statements correctly describe the r ...