8/16/2006
 

Feedback for starting log blog


Well, I am already receiving feedback from the log analysis list.
I have a few folks who want to offer logs. I also have feedback from the same person who inspired me to get log-blog back into use.
Hmm, pls don't call me a curmudgeon  :-) , but this effort is largely
doomed to fail.
...people are not too motivated to share their logs (samples, etc)...
Tina (Bird) and Marcus Ranum tried to collect a lot on loganalysis.org, but
their project stalled for that very reason...
OK. While I have no where near the smarts of Marcus Ranum, Tina Bird, or Anton Chuvakin, I am still willing to give it a go. I think I have one insight that could help with getting content. I have been on the log analysis list for two years now. At the same time I have been on other lists for products that parse/correlate/collect logs. I have seen very few names that post across the lists. Hence I may get more cooperation if I target needs across the other lists. If it does not work out, then hey what have I lost? So far I haven't spent a dime and this allows me to put a little more effort into something I find interesting. Hence I think "doomed to fail" is a little harsh.
Comments:
What other lists are you referring to? firewall-wizards? focus-ids? Or..?
 
I am thinking of lists like simple event correlator (sec) and other lists that are specific to a tool that handles a variety of logs. I know the other lists you mentioned are popular.
 
Post a Comment

<< Home

This page is powered by Blogger. Isn't yours?