Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 5675
  • Last Modified:

Netflow vs. Syslog

Hello-
I am trying to do some audti/monitorng on my network equiptment (primarily Cisco).  I am trying to understand the difference between Netflow and Syslog messages and when would I use one vs. the other.  Many thanks!
0
jfexchange
Asked:
jfexchange
2 Solutions
 
lrmooreCommented:
Netflow gives you excellent insight into connections - who's talking to whom, but what protocol and for how long. Qualify/quantify all your traffic with ease.
Syslog sends/gets all the system messages, error messages, IDS messages, etc. Identify high CPU utilzation, access-list hits, system errors, interface down messages, etc.
It is best to have both!

0
 
v_karthikCommented:
Netflow gives u traffic and usage information, but syslog notifies u about the "problems" in the network. The problems can be just notifications that an interface went down / came up, configuration on a device changed etc. or something very serious as internal errors, memory problems etc.

Its good to have both, but if you just want to do basic fault management in a stable network, use syslog.

For netflow, you can try cisco ios netflow software.  For syslog analysis, you can use syslogd if you are on unix, or winsyslog, kiwisyslog etc. if you are on windows. Cisco's network management suite called Resource Manager Essentials (RME) comes with a syslog analyzer application that gives you a lot of features like notification through email on a certain pattern of syslog. You'll also be able to generate a variety of reports for future analysis.
0

Featured Post

Granular recovery for Microsoft Exchange

With Veeam Explorer for Microsoft Exchange you can choose the Exchange Servers and restore points you’re interested in, and Veeam Explorer will present the contents of those mailbox stores for browsing, searching and exporting.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now