Solved

Log Analyzer for Cisco PIX/ASA?

Posted on 2006-11-20
13
1,739 Views
Last Modified: 2013-11-16
Hi.  I would like know what are the log analyzers out there for collecting and analyzing logs from Cisco PIX/ASA, or Cisco Routers?  ANy suggestions?
0
Comment
Question by:hoggiee
  • 3
  • 2
  • 2
  • +2
13 Comments
 
LVL 51

Accepted Solution

by:
Keith Alabaster earned 75 total points
ID: 17978863
0
 
LVL 32

Assisted Solution

by:rsivanandan
rsivanandan earned 75 total points
ID: 17979048
For free, I'll add this;

Kiwi syslog (google it and you'll get it)

Cheers,
Rajesh
0
 
LVL 16

Expert Comment

by:The_Kirschi
ID: 17980882
http://www.cisco.com/en/US/products/ps6241/products_data_sheet0900aecd80272e64.html

Not cheap but nice tool. If you want to use it depends on the size of your environment I think.
0
 
LVL 23

Assisted Solution

by:Tim Holman
Tim Holman earned 75 total points
ID: 17983156
Sawmill is quite good too:

http://www.thesawmill.co.uk

Or Kiwi -

http://www.kiwisyslog.com

How many Cisco devices do you have?  If you have a lot, then something more enterprise oriented (www.eiqnetworks.com) would be more suitable.
0
 

Author Comment

by:hoggiee
ID: 17984241
I intend to collect logs from 5 Cisco ASA and 1 Cisco router.  I need something that can offer detailed analysis of logs and report generation e.g. all incoming and outgoing traffic, all blocked traffic, attempted access blocked by the device, etc.  Therefore, I do not think kiwi syslog is a good option.
0
What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

 

Author Comment

by:hoggiee
ID: 17984253
and not to be left out, alerts and notification of any failed events.....
0
 
LVL 16

Assisted Solution

by:The_Kirschi
The_Kirschi earned 75 total points
ID: 17985486
So I think my suggestion would fit into your environment.
0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 17985623
Have you looked at AdventNet stuff which works on SNMP and also is free for 5 devices.

http://www.adventnet.com/products/webnms/index.html

Cheers,
Rajesh
0
 
LVL 23

Expert Comment

by:Tim Holman
ID: 17985845
Do you have a budget, or are you after freeware?
0
 

Author Comment

by:hoggiee
ID: 18065349
Have tried out a few of them, and found out in the end that EIQ's Network Security Analyzer seems the most appropriate solution to my environment.  By the way, I have also found out that Sawmill doest not offer a syslog server to capture the syslogs from my Cisco devices.
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 18066692
:)
0

Featured Post

Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

Join & Write a Comment

Suggested Solutions

Do you have a windows based Checkpoint SmartCenter for centralized Checkpoint management?  Have you ever backed up the firewall policy residing on the SmartCenter?  If you have then you know the hassles of connecting to the server, doing an upgrade_…
The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
This video explains how to create simple products associated to Magento configurable product and offers fast way of their generation with Store Manager for Magento tool.

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now