<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss'><id>tag:blogger.com,1999:blog-11110801</id><updated>2009-02-21T00:59:07.422-08:00</updated><title type='text'>Log-Blog</title><subtitle type='html'>A blog about computer network logging. It includes syslog, windows event logs, application specific logs and the tools to parse and correlate them.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://log-blog.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11110801/posts/default'/><link rel='alternate' type='text/html' href='http://log-blog.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>D. Alan Ridgeway</name><uri>http://www.blogger.com/profile/12947995376844264178</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>3</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-11110801.post-115577850554170355</id><published>2006-08-16T18:29:00.000-07:00</published><updated>2006-08-16T18:35:05.550-07:00</updated><title type='text'>What logs do you want to see?</title><content type='html'>As stated earlier, I do have offers from some people for logs and I track some lists and have a sense of what they are looking for. But what I would like to know is what logs are you looking for first? What do you need from the logs? Do you need a filtered group of entries that just shows IPSec conenctions for a Cisco PIX? Do you want to see many different Anti-Virus vendors log for the same virus/worm? What is it you want to get the most out of logs at this time?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11110801-115577850554170355?l=log-blog.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://log-blog.blogspot.com/feeds/115577850554170355/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=11110801&amp;postID=115577850554170355' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11110801/posts/default/115577850554170355'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11110801/posts/default/115577850554170355'/><link rel='alternate' type='text/html' href='http://log-blog.blogspot.com/2006/08/what-logs-do-you-want-to-see.html' title='What logs do you want to see?'/><author><name>D. Alan Ridgeway</name><uri>http://www.blogger.com/profile/12947995376844264178</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='06604183372368728764'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11110801.post-115577657605610879</id><published>2006-08-16T17:37:00.000-07:00</published><updated>2006-08-16T18:02:56.096-07:00</updated><title type='text'>Feedback for starting log blog</title><content type='html'>Well, I am already receiving feedback from the log analysis list.&lt;br /&gt;I have a few folks who want to offer logs. I also have feedback from the same person who inspired me to get log-blog back into use.&lt;br /&gt;&lt;pre&gt;Hmm, pls don't call me a curmudgeon  :-) , but this effort is largely&lt;br /&gt;doomed to fail.&lt;br /&gt;...people are not too motivated to share their logs (samples, etc)...&lt;br /&gt;Tina (Bird) and Marcus Ranum tried to collect a lot on loganalysis.org, but&lt;br /&gt;their project stalled for that very reason...&lt;br /&gt;&lt;/pre&gt;OK. While I have no where near the smarts of Marcus Ranum, Tina Bird, or Anton Chuvakin, I am still willing to give it a go. I think I have one insight that could help with getting content. I have been on the log analysis list for two years now. At the same time I have been on other lists for products that parse/correlate/collect logs. I have seen very few names that post across the lists. Hence I may get more cooperation if I target needs across the other lists. If it does not work out, then hey what have I lost? So far I haven't spent a dime and this allows me to put a little more effort into something I find interesting. Hence I think "doomed to fail" is a little harsh.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11110801-115577657605610879?l=log-blog.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://log-blog.blogspot.com/feeds/115577657605610879/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=11110801&amp;postID=115577657605610879' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11110801/posts/default/115577657605610879'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11110801/posts/default/115577657605610879'/><link rel='alternate' type='text/html' href='http://log-blog.blogspot.com/2006/08/feedback-for-starting-log-blog.html' title='Feedback for starting log blog'/><author><name>D. Alan Ridgeway</name><uri>http://www.blogger.com/profile/12947995376844264178</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='06604183372368728764'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11110801.post-115569766043413288</id><published>2006-08-15T20:00:00.000-07:00</published><updated>2006-08-15T21:00:08.213-07:00</updated><title type='text'>Log-blog reloaded</title><content type='html'>&lt;span style="font-weight: bold;"&gt;touch /var/log/log-blog &amp;&amp;amp; kill -HUP `lsof -t -c syslog-ng`&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;After a year of ignoring log-blog I decided to give it another go. I was inspired by two events.&lt;br /&gt;1) I was just informed that I am one of 1700 people to get laid off from CA.&lt;br /&gt;2) Anton Chuvakin posted the following challenge on the Log Analysis list.&lt;br /&gt;&lt;pre wrap=""&gt;He-he, everybody is looking for it and nobody is creating it &lt;span class="moz-smiley-s1"&gt; :-) &lt;/span&gt;&lt;/span&gt;&lt;font&gt;&lt;br /&gt;&lt;span class="moz-txt-citetags"&gt;&gt; &lt;/span&gt;I was curious if anyone knows of a resource that provides a many&lt;br /&gt;&lt;span class="moz-txt-citetags"&gt; &lt;/span&gt;examples of the various logs from many devices and vendors?&lt;/span&gt;&lt;/pre&gt;&lt;/font&gt;Hence I am willing to create it.&lt;br /&gt;More details to follow very soon&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11110801-115569766043413288?l=log-blog.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://log-blog.blogspot.com/feeds/115569766043413288/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=11110801&amp;postID=115569766043413288' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11110801/posts/default/115569766043413288'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11110801/posts/default/115569766043413288'/><link rel='alternate' type='text/html' href='http://log-blog.blogspot.com/2006/08/log-blog-reloaded.html' title='Log-blog reloaded'/><author><name>D. Alan Ridgeway</name><uri>http://www.blogger.com/profile/12947995376844264178</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='06604183372368728764'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>1</thr:total></entry></feed>