Topic
2 replies Latest Post - ‏2008-03-12T12:34:30Z by SystemAdmin
SystemAdmin
SystemAdmin
232 Posts
ACCEPTED ANSWER

Pinned topic Bash script for server log (namely var/log/messages)

‏2007-05-17T23:28:54Z |
Hi all,

I need a bash script to traverse a filesystem from a server, and look for suspicious activity. This is mainly suspicious activity in the messages log, such as port probing from the same ip address, repeated failed login attempts etc.

Ive managed to traverse the filesystem but could do with a hand on looking for suspicious activity as I am not used to checking server logs.

Any help with the script or how to identify indicators of suspicious activity would be gratefully received.

Kind Regards

Rich9581
Updated on 2008-03-12T12:34:30Z at 2008-03-12T12:34:30Z by SystemAdmin
  • SystemAdmin
    SystemAdmin
    232 Posts
    ACCEPTED ANSWER

    Re: Bash script for server log (namely var/log/messages)

    ‏2007-12-04T21:31:09Z  in response to SystemAdmin
    I have not used it myself, but splunk is supposed to be helpful in searching your logfiles. You also might want to install logwatch.
  • SystemAdmin
    SystemAdmin
    232 Posts
    ACCEPTED ANSWER

    Re: Bash script for server log (namely var/log/messages)

    ‏2008-03-12T12:34:30Z  in response to SystemAdmin
    send me your requirment my mail id clearly letz try to help!!!!1
    arunkumargowdar@gmail.com