FirewallWizards
[Top] [All Lists]

Re: [fw-wiz] [OT?] Accounting from PIX Logs

To: "Brian Ford (brford)" <brford@cisco.com>
Subject: Re: [fw-wiz] [OT?] Accounting from PIX Logs
From: fRANz <andrea.francesconi@gmail.com>
Date: Wed, 28 Mar 2007 19:15:53 +0200
Cc: firewall-wizards@listserv.cybertrust.com
Delivered-to: sp-com-lists@consult.net
Delivered-to: fwwizards-list2@consult.net
Delivered-to: firewall-wizards@listserv.cybertrust.com
In-reply-to: <711A1D9897F2F04B9C166616EC8ED93E0308EF84@xmb-rtp-209.amer.cisco.com>
List-archive: <https://listserv.icsalabs.com/pipermail/firewall-wizards>
List-help: <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=help>
List-id: Firewall Wizards Security Mailing List <firewall-wizards.listserv.icsalabs.com>
List-post: <mailto:firewall-wizards@listserv.icsalabs.com>
List-subscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=subscribe>
List-unsubscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=unsubscribe>
References: <mailman.712.1175087020.23601.firewall-wizards@listserv.icsalabs.com> <711A1D9897F2F04B9C166616EC8ED93E0308EF84@xmb-rtp-209.amer.cisco.com>
Reply-to: Firewall Wizards Security Mailing List <firewall-wizards@listserv.icsalabs.com>
Sender: firewall-wizards-bounces@listserv.icsalabs.com
On 3/28/07, Brian Ford (brford) <brford@cisco.com> wrote:

> Franz,
>
> I wouldn't consider this OT at all.

Hi Brian,

thank you for your reply.

> So given that you are considering summarizing data from the PIX logs;
> what kinds of data are you looking for in this summary?

It isn't a security log analysis.
At this moment, I think connection traffic (for any single connection
in connection tracking) is the best information that I've to manage.

> You also said "accounting"; by that did you mean checking to see if you
> had log data missing or actually looking in the log data for accounting
> details?

Accounting by internal IP address, by protocol, etc... (possibly sorted).
Like a "report" related to time unit...

Regards,
-f
_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

<Prev in Thread] Current Thread [Next in Thread>