<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: dimitri]]></title>
    <link>http://securityratty.com/tag/dimitri</link>
    <description></description>
    <pubDate>Mon, 21 Apr 2008 16:59:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Fun Reading on Logs and Log Management - 2]]></title>
      <link>http://securityratty.com/article/dac0b52428267c699e6e37706f29fb2a</link>
      <guid>http://securityratty.com/article/dac0b52428267c699e6e37706f29fb2a</guid>
      <description><![CDATA[I am amazed (no, AMAZED!) about how many people now write about logs; it is definitely not &quot;the original logging evangelist&quot; anymore :-) Here is a bunch of good log-related reading, useful for those...]]></description>
      <content:encoded><![CDATA[<p>I am amazed (no, AMAZED!) about how many people now write about logs; it is definitely not <a href="http://www.chuvakin.org">&quot;the original logging evangelist&quot;</a> anymore :-) Here is a bunch of good log-related reading, useful for those struggling with logs (aka &quot;everybody&quot; :-))</p>  <ol>   <li>Our brilliant field engineer Dimitri McKay <a href="http://www.dimitrimckay.com/Loglogic/Blog/Entries/2008/7/20_How_to_convert_windows_logs_to_syslog:.html">talks about</a> the eternal topic of converting Windows event logs to syslog. <a href="http://blogs.msdn.com/ericfitz/">Yes, Eric, we ALL know</a> it is ugly, but that is the only way that actually works well across all systems ...</li>    <li>More on Windows and syslog: &quot;<a href="http://redmondmag.com/columns/article.asp?editorialsid=1868">Syslog ... 20 Years Later</a>.&quot;&#160; BTW, this is really not about syslog, but about Vista/2k8 finally getting an ability to natively centralize the event logs via event subscriptions (&quot;It's only about twenty years behind schedule, if you're counting.&quot;)</li>    <li>Two fun pieces on correlation: <a href="http://www.rsa.com/blog/blog_entry.aspx?id=1301">1</a> and <a href="http://blog.isc2.org/isc2_blog/2008/09/event-correlati.html">2</a>. What often kills &quot;a log correlation project&quot;? &quot;Whoever had worked on it <em>had not had much time available to learn the way to properly configure the software</em>&quot; (from <a href="http://blog.isc2.org/isc2_blog/2008/09/event-correlati.html">this</a>)&#160; and &quot;correlation only really works when backed up by real data about what is the biggest problem in your environment, and how that problem manifests itself in the event logs.&quot; (from <a href="http://www.rsa.com/blog/blog_entry.aspx?id=1301">this</a>) None of this is new, but a useful reminder nonetheless</li>    <li>Fun <a href="http://www.loglogic.com">LogLogic</a> podcast is <a href="http://blogs.zdnet.com/Gardner/?p=2723">here</a>. The topic of this high-level discussion (CEO) is related to operational use for logs. I did one with them too; on logs and virtualization (will be up soon)</li>    <li>A couple of good posts on logging from Nemertes Research: &quot;<a href="http://www.nemertes.com/analyst_blogs/sharpening_stones_and_walking_coals">Sharpening Stones and Walking on Coals</a>&quot;,&#160; &quot;<a href="http://www.nemertes.com/analyst_blogs/search_or_destroy">Search or Destroy</a>&quot;</li>    <li><a href="http://eventlogs.blogspot.com/2008/08/why-your-hr-department-will-love.html">Reminder</a> about a few useful Windows Vista and 2k8 events: 4802 (screensaver engaged) and 4803 (screensaver dismissed)</li>    <li><a href="http://jdm-tech.blogspot.com/2008/07/how-worthwhile-is-logging.html">One person is wondering</a> about the usefulness of logging after &quot;experiencing&quot; Linux auditd logging (kernel audit): &quot;Logs are like a warm blanket; verbose logging means you can know what's happening on your systems if you keep up with the logs.&#160; At the same time, logs become a burden very very easily, and they are easy to ignore.&quot; <a href="http://jdm-tech.blogspot.com/2008/07/how-worthwhile-is-logging.html">This post</a> is a must read for <a href="http://www.chuvakin.org">us logging afficionados</a>; producing too much log data is a sure way to make people hate you...</li>    <li><a href="http://thomasnicholson.com/2008/07/02/log-management-is-a-pain/">This</a> also follows the same theme: people doubting the god-like power of logs :-) &quot;So for an administrator to not care about logs was a shock.&quot; But would I argue that &quot;<a href="http://thomasnicholson.com/2008/07/02/log-management-is-a-pain/">log management is NOT a pain?</a>&quot; Now, would I? :-)</li>    <li>A classic about logging for application developers: &quot;<a href="http://www.securityfocus.com/infocus/1888">Building Secure Applications: Consistent Logging</a>.&quot;&#160; I am noticing a lot more discussions about logging in a developer community, e.g. see <a href="http://ayende.com/Blog/archive/2008/08/02/Logging-Auditing-and-Alerts.aspx">this</a> and <a href="http://www.softwaremag.com/l.cfm?doc=1048-5/2007">this</a> (the latter, BTW, contains a lot of info on &quot;why log&quot; for developers). Overall, &quot;getting logging right&quot; is important (and will get more important in the future) and people need something NOW and cannot wait for the <a href="http://cee.mitre.org">standards.</a>&#160; BTW, I am planning a mini-crusade on how to train application developers to include useful logging in their applications...</li>    <li>Finally, the &quot;Is SIEM dead?&quot; theme is continued in this fun post &quot;<a href="http://blogs.splunk.com/thebaum/2008/09/03/situational-awareness/">Life after SIEM. Situational Awareness is next.</a>&quot; Indeed, <a href="http://chuvakin.blogspot.com/2008/06/logging-poll-8-analysis-needed-log.html">context is key for logs</a>. BTW, if somebody mentions that I have &quot;vendor bias&quot;, I will kick your ass! :-)</li> </ol>  <p>Enjoy!</p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=gABUL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=gABUL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=5mpyL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=5mpyL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=AMhOL"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=AMhOL" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/393291744" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 04:03:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/logs">logs</category>
      <category domain="http://securityratty.com/tag/windows event logs">windows event logs</category>
      <category domain="http://securityratty.com/tag/event logs">event logs</category>
      <category domain="http://securityratty.com/tag/log management">log management</category>
      <category domain="http://securityratty.com/tag/log">log</category>
      <category domain="http://securityratty.com/tag/developers">developers</category>
      <category domain="http://securityratty.com/tag/train application developers">train application developers</category>
      <category domain="http://securityratty.com/tag/log correlation project">log correlation project</category>
      <category domain="http://securityratty.com/tag/application developers">application developers</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/393291744/fun-reading-on-logs-and-log-management.html">Fun Reading on Logs and Log Management - 2</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-05-14 [del.icio.us]]]></title>
      <link>http://securityratty.com/article/97efd7aa78e9d1aad8d73d1488b06061</link>
      <guid>http://securityratty.com/article/97efd7aa78e9d1aad8d73d1488b06061</guid>
      <description><![CDATA[Nerd News: Dimitri SIEM vs LMI
GRC, Average Deal Size, And The Dangers Of Venture Capital | securosis.com
The Security Roundtable Security Roundtable for May 2008 | RSA Conference - Beyond the Hype...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://www.dimitrimckay.com/Loglogic/Blog/Entries/2008/5/13_SIEM_vs._LMI%3A_Why_limit_correlation.html">Nerd News: Dimitri SIEM vs LMI</a></li>
<li><a href="http://securosis.com/2008/05/14/grc-average-deal-size-and-the-dangers-of-venture-capital/">GRC, Average Deal Size, And The Dangers Of Venture Capital | securosis.com</a></li>
<li><a href="http://www.securityroundtable.com/2008/05/14/security-roundtable-for-may-2008-rsa-conference-beyond-the-hype/">The Security Roundtable &raquo; Security Roundtable for May 2008 | RSA Conference - Beyond the Hype</a></li>
<li><a href="http://www.realtime-itcompliance.com/information_security/2008/04/smart_business_leaders_support.htm">Smart Business Leaders Support Effective Log Management Practices and Necessary Resources - Realtime IT Compliance</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/290668216" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 14 May 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nerd news">nerd news</category>
      <category domain="http://securityratty.com/tag/dimitri siem">dimitri siem</category>
      <category domain="http://securityratty.com/tag/rsa conference">rsa conference</category>
      <category domain="http://securityratty.com/tag/average deal">average deal</category>
      <category domain="http://securityratty.com/tag/venture capital">venture capital</category>
      <category domain="http://securityratty.com/tag/compliance">compliance</category>
      <category domain="http://securityratty.com/tag/resources">resources</category>
      <category domain="http://securityratty.com/tag/hype">hype</category>
      <category domain="http://securityratty.com/tag/grc">grc</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/290668216/anton18">Links for 2008-05-14 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[More on "Enterprise-Class" (or Enterprise-Quality)]]></title>
      <link>http://securityratty.com/article/4dd8d6f3042eeb6f2a40f6962bf79777</link>
      <guid>http://securityratty.com/article/4dd8d6f3042eeb6f2a40f6962bf79777</guid>
      <description><![CDATA[Mike R makes what I consider to be an absurd claim here : &quot;... How can Baracuda sell an anti-spam gateway for $3000 and other vendors sell a similar product for $50,000? Is the other product 15 times...]]></description>
      <content:encoded><![CDATA[Mike R makes what I consider to be an absurd claim <a href="http://securityincite.com/TDI-2008-04-21#TBP2">here</a>: "... How can Baracuda sell an anti-spam gateway for $3000 and other vendors sell a similar product for $50,000? <span style="font-weight: bold;">Is the other product 15 times better? Of course not.</span> But the enteprise customers in an early market can afford $50K per box, so that's what you charge them. "<br /><br />Honestly, I am not sure about the anti-spam gateways, they might be all the same indeed (and so Mike might actually be right about that specific type of a product...), but I can tell you that in <a href="http://www.loglogic.com">log management</a> the answer "<span style="font-weight: bold;">Yes, it is <span style="font-style: italic;">that much better </span>in features that actually make it 'enterprise'</span>" - see <a href="http://blog.loglogic.com/2007/10/just_what_is_enterprise_class_part_v/">this five-part treatise on that very subject</a> by our <a href="http://www.dimitrimckay.com/Loglogic/Blog/Blog.html">enlightened System Engineer Dimitri McKay</a>.<br /><br />You can get Sawmill for $0, you can get whatever other product for $5k - or you can get <a href="http://www.loglogic.com">LogLogic</a>. The difference in what you will get will be about the same as the price factor!<br /><br />All this debate is BTW inspired by <a href="http://1raindrop.typepad.com/1_raindrop/2008/04/rsa-debrief-11.html">this RSA-related piece</a>.<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=20l8enG"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=20l8enG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=3eLKHXG"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=3eLKHXG" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/275148063" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 21 Apr 2008 16:59:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/product">product</category>
      <category domain="http://securityratty.com/tag/similar product">similar product</category>
      <category domain="http://securityratty.com/tag/log management">log management</category>
      <category domain="http://securityratty.com/tag/afford 50k">afford 50k</category>
      <category domain="http://securityratty.com/tag/mike">mike</category>
      <category domain="http://securityratty.com/tag/price factor">price factor</category>
      <category domain="http://securityratty.com/tag/anti-spam gateway">anti-spam gateway</category>
      <category domain="http://securityratty.com/tag/enterprise">enterprise</category>
      <category domain="http://securityratty.com/tag/anti-spam gateways">anti-spam gateways</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/275148063/more-on-enterprise-class-or-enterprise.html">More on "Enterprise-Class" (or Enterprise-Quality)</source>
    </item>
  </channel>
</rss>
