Home > Security Tips > Scott Sidel's Downloads > Review system event logs with Splunk
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SCOTT SIDEL'S DOWNLOADS

Review system event logs with Splunk


Scott Sidel, Contributor
11.24.2008
Rating: -4.00- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Logging and log review are two of the most difficult challenges faced by security pros. Even if a person is dedicated to nothing but log review, he or she would be quickly overwhelmed by the volume of information and the tedium of the task. That's why dedicated log-review systems are a must, and there's a tool for the job that's simple but powerful -- and free.

Splunk is a great tool for grabbing all sorts of network data, making it simple to search, providing triggers and alerts, keeping the data secure with granular access controls and offering controls for data audit and data integrity.

Splunk allows a variety of inputs, including logs, configuration files, traps and alerts, device and system messages, scripts, and performance data from applications, servers and networked devices. The software monitors file systems for configuration changes, watches files and logs, and can connect to network ports to receive syslog, SNMP and other network-based data. The Web interface uses drop-down boxes, making it easy to select a file to monitor, such as an actively growing log file, showing the most recent updates first.

Point Splunk to a file and it will intelligently parse the file, working out the event-types and normalizing a multitude of timestamp formats across different log types. Data is parsed and indexed on-the-fly, while raw events are kept for review. The data is secured with an MD5 hash using a PKI signature to detect tampering and point out gaps in the log where specific data may have been deleted. The tool keeps an audit record of who administers the system and who accesses data.

Splunk supports free-form search, but has a few tricks up its sleeve, such as a pop-up wind



ow with common events and values from logs to allow the administrator to zero in on specific behaviors, such as server errors.

Searches can be run on a schedule and set to trigger notifications or actions based on search results. Alerts can be used to monitor user or system activity and can trigger based on event types, event source or even the number of events; alerts can also trigger scripts to perform an action, such as restarting an application or service when it detects a condition. Notifications can be sent via email, RSS or Simple Network Management Protocol (SNMP) to other management consoles.

For security, Splunk uses SSL over TCP to secure the data-path. User sessions with the browser are performed using HTTPS over SSL. Roll-based access supports multiple types of users and comes with pre-built roles that can be modified or supplemented. Splunk integrates with Active Directory, LDAP and other directory services.

The biggest difference between the free version of Splunk and the commercial version is a cap that limits the maximum indexing volume to 500 MB per day. While meant to entice users to try Splunk, this volume cap may suffice for many small organizations.

Splunk works across a variety of platforms and deploys fairly quickly. It has an intelligently thought-out interface, which makes it relatively easy to use. If your company is looking for a product that offers log collection, review, searching, parsing and alerting -- for free -- Splunk may provide a smart and secure way to get the job done.

About the author:
Scott Sidel is an ISSO with Lockheed Martin. For more recommendations from the author, check out Scott Sidel's Downloads.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Scott Sidel's Downloads,   Network Intrusion Detection and Analysis,   Enterprise Network Security,   Security Event Management,   Monitoring Network Traffic and Network Forensics,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Scott Sidel's Downloads
Use BotHunter for botnet detection
FISMA compliance made easier with OpenFISMA
Ophcrack: Password cracking made easy
Enigmail: Wrapping email in a digital security blanket
Secure file copying with WinSCP
FreeRADIUS: Acing a secure connection
Spiceworks: Free network monitoring and management with a little zest
VirusTotal: On-demand antivirus service scans malicious files
Shining a spotlight on rootkits
Closing the case on network firewall security with IPCop

Security Event Management
Mature SIMs do more than log aggregation and correlation
SIMs tools and tactics for business intelligence
SIEM: Not for small business, nor the faint of heart
Should IDS and SIM/SEM/SIEM be used for network intrusion monitoring?
Tying log management and identity management shortens incident response
How to estimate log generation rates
SANS Log Management Survey is "Looking for the ROI"
Virtual network tool gives firm view into virtualized environment
Mining enterprise SIM logs for relevant security event data
Quiz: Getting the most out of your SIM deployment

Monitoring Network Traffic and Network Forensics
Chained Exploits: How to prevent phishing attacks from corporate spies
PCI compliance requirement 10: Auditing
Know when you need IDS, IPS or both
An inside look at security log management forensics investigations
How to analyze a TCP and UDP network traffic spike
How to perform a network forensic analysis and investigation
Tying log management and identity management shortens incident response
The telltale signs of a network attack
Cyberattack mapping could alter security defense strategy
Should the government reduce its external Internet connections?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
computer forensics  (SearchSecurity.com)
Einstein  (SearchSecurity.com)
footprinting  (SearchSecurity.com)
information signature  (SearchSecurity.com)
inverse mapping  (SearchSecurity.com)
network behavior analysis  (SearchSecurity.com)
network forensics  (SearchSecurity.com)
probe  (SearchSecurity.com)
promiscuous mode  (SearchSecurity.com)
snoop server  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
More Security Resources for Resellers, VARs and OEMs
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts