NetScreen
[Top] [All Lists]

[nn] Script or perl regex(es) for marking up Netscreen event/alert logs

To: nn@qorbit.net
Subject: [nn] Script or perl regex(es) for marking up Netscreen event/alert logs with useful embedded URLs?
From: Chris Dagdigian <dag@sonsorol.org>
Date: Fri, 9 Mar 2007 07:43:56 -0500
Delivered-to: sp-com-lists@consult.net
Delivered-to: ns-list2@consult.net
Delivered-to: nn@qorbit.net
List-archive: <http://www.qorbit.net/nn>
List-help: <mailto:nn-request@qorbit.net?subject=help>
List-id: "Netscreen mailing list for netscreen admins." <nn.qorbit.net>
List-post: <mailto:nn@qorbit.net>
List-subscribe: <http://qorbit.net/mailman/listinfo/nn>, <mailto:nn-request@qorbit.net?subject=subscribe>
List-unsubscribe: <http://qorbit.net/mailman/listinfo/nn>, <mailto:nn-request@qorbit.net?subject=unsubscribe>
Sender: nn-bounces@qorbit.net
I maintain ~4 Netscreen devices, not enough to justify diving into  
the NSM software world ...

Currently all 4 devices syslog to a central server where I use swatch  
to parse out the interesting events and pass them on to an internal  
mailing list.

The emails are pretty dry, consisting only of the "interesting"  
netscreen alert messages concatenated together.

I've been thinking that it would be pretty easy to post-process those  
event logs so that (for instance) HTML markup can be embedded so that  
the attack signature ID is wrapped in a HTML link to the online  
knowledge base describing the attack. The same thing for any IP or  
network data -- wrap those octets in a link that points to an online  
tool allowing reverse-lookups, whois research, etc. etc.

Has anyone already done this? Since I read the alerts on my phone or  
laptop, both of which have "HTML aware" email clients this would make  
the Netscreen alerts slightly more useful, usable and informative.   
I'm not looking to reinvent the wheel though so I figured I'd ask if  
someone has already done this.  Any tools  out there for processing  
Netscreen alert logs?

Regards,
Chris

_______________________________________________
nn mailing list
nn@qorbit.net
http://qorbit.net/mailman/listinfo/nn

<Prev in Thread] Current Thread [Next in Thread>
  • [nn] Script or perl regex(es) for marking up Netscreen event/alert logs with useful embedded URLs?, Chris Dagdigian <=