Cisco syslog analysis tool

Posted on 2009-05-04
Last Modified: 2013-12-07
I am looking for some Cisco syslog analysis tool, software that will take a large amount of data and try to identify possible intrusion...

Any such software out there?
Question by:SPERTW
LVL 19

Expert Comment

ID: 24301301

the kiwisyslog viewer and sawmill syslog viewer are both v good - try em out and see what you think

LVL 32

Accepted Solution

Kamran Arshad earned 250 total points
ID: 24301597

If it is just a syslog manager then you can check out any of the below solutions;

Lire      Open-Source
Epylog Log Analyzer      Open-Source
SLAPS-2      Open-Source
Sisyphus      Open-Source
LogHound      Open-Source
syslog-ng      Open-Source
SysLog Manager      Propriety
WinSyslog      Propriety
syslog_manager      Propriety
logserver      Propriety
Syslog Watcher      Propriety
tftpd3d      Propriety
Syslog Collector      Propriety
NetDecision LogVision      Propriety
KiwiSysLog      Propriety
SolarWinds      Propriety

But I feel that you are using pix firewall or something similar and you need more details. For that purpose you need a firewall analyzer. Below are good list;

Adventnet Firewall Analyzer
AlgoSec Firewall Analyzer
Firewall Analyzer

Author Comment

ID: 24304859
Thanks for the reply!

You guys given me so many choices!

We would prefer a software vendor that will have support, which one would be a better choice?


Expert Comment

ID: 24306455
I use Kiwi Syslog and they have pretty decent support. They're newest beta version has a Web Interface that you can access as well to see the messages.

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

Large and small networks have one same need, Service monitoring. Service monitoring consists of watch services of the several servers in the network. To monitor means that the administrator will receive an alert when a service is down or it's state …
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
Here's a very brief overview of the methods PRTG Network Monitor ( offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor ( If you're looking for how to monitor bandwidth using netflow or packet s…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now