Interpreting a Logfile with Grok

Main Author: Rocco Gagliardi
Other Authors: Marc Ruef
Format: Article Journal
Bahasa: eng
Terbitan: , 2013
Subjects:
Mac
Online Access: https://zenodo.org/record/3521218
Daftar Isi:
  • We have a BSM audit log, iptable log, Apache, smbd_audit log. How can we normalize the useful information and extract/correlate what we need? A small piece of software can make our life easier: Grok.
  • This paper was written in 2013 as part of a research project at scip AG, Switzerland. It was initially published online at https://www.scip.ch/en/?labs.20130405 and is available in English and German. Providing our clients with innovative research for the information technology of the future is an essential part of our company culture.