The BSD syslog Protocol (RFC 3164)

Security Issues in Network Event Logging (syslog)

Reliable Delivery for syslog (txt)

Log Analysis Org

Digesting log data Part I, Part II

Forwarding Windows Events via stunnel to a UNIX/Linux syslogd

Comparison of Adiscon's Windows logging products

Performance Optimizing Syslog Server

Tina's SANS Webcast: Top Ten syslog Signs You Have Been Hacked (pdf)

A Guide to Understanding Audit in Trusted Systems

*Active Security Monitoring and Containment with Cross Technology Correlation: The Next Generation in Computer Security Technology

Manage logging and other data collection mechanisms

Common Log Format

Logging via Syslog

*Automated Auditing in a Windows 2000 Environment

Visual Studio Analyzer - Event Log Basics (MSDN)

An event log is a binary file where Visual Studio Analyzer stores the events it collects. This event log can be read only through the Visual Studio Analyzer user interface or programmatically through the automation model. After you create a recording filter and started recording, an event log is created automatically. Visual Studio Analyzer collects the events that your application generates into that event log. You can then pause, resume, stop recording, or play back the events in that event log.

How to Determine Audit Policies from the Registry (MS KB 246120)

Monitoring Windows NT/2000/XP/2003

Microsoft Solution for Securing Windows 2000 Server: Chapter 9 - Auditing and Intrusion Detection

Detecting Password Attacks on Windows

Practical Implementations of syslog in Mixed Windows Environments for Secure Centralized Audit Logging (pdf)

Miscellaneous Notes on Windows Logging

Dealing with Windows NT Event Logs. Part I, Part II.

Event Reference

EventID.Net

How To Prevent Auditable Activities When Security Log Is Full (MS KB 140058)

W2K and NT Security Event Log Descriptions

PsLogList

The Resource Kit comes with a utility, elogdump, that lets you dump the contents of an Event Log on the local or a remote computer. PsLogList is a clone of elogdump except that PsLogList lets you login to remote systems in situations your current set of security credentials would not permit access to the Event Log, and PsLogList retrieves message strings from the computer on which the event log you view resides.

WinSyslog

An RFC3195 implementation for Windows (logger.zip)

Kiwi Syslog Daemon

Syslog Turbo

Simple syslog wrapper

Freeware syslog/tftpserver/tftpclient/ftp server (3cDaemon - 3cdv2r10.zip)

Snare Agent for Windows

NTsyslog

EventReporter - The NT Event Monitor

Perl script that scans NT Event Logs periodically

Syslog for Windows NT (SL4NT)

Kiwi SyslogGen

How to Use Logevent.exe to Log Events From a Batch File (MS KB 131008)

*HealthMonitor

Log consolidation with syslog (pdf)

Syslog-ng

*Centralized syslog-ng to Mysql Installation Guide

Tuning Syslog-ng on Gentoo Linux (Big5)

Nate Campi's sample syslog-ng configuration file

Nate Campi's sample syslog-ng config for Solaris

Encrypting traffic to a remote syslog-ng server including SSL peer authentication

鳥哥的 Linux 與 ADSL 私房菜 - 認識與分析登錄檔 (Big5)

Building Secure Servers With Linux" (O'Reilly and Associates) covering syslog-ng (pdf)

SDSC Secure Syslog

Syslog Analysis

Minirsyslogd

Nsyslogd

IDSA Logging

OSSP l2 Flexible Logging

sysklogd

Modular syslog

Seure syslog tools

Socklog - System and kernel logging services

InterSect Alliance's System iNtrusion Analysis and Reporting Environment (SNARE)

Multilog

Jeff Saxe's intro to multilog

Logging Syslog to a Database

Central Loghost Mini-HOWTO

Centralized Logging using Logsentry in a Large UNIX Environment (doc)

Complete Reference Guide to Creating a Remote Log Server

Advanced Log Processing

Configuring and using syslogd to collect logging messages on systems running Solaris 2.x

Introduction to system logging

Keeping Track of What Goes On: Part I

Know Your Enemy: II - Tracking the blackhat's moves

Extending UNIX System Logging with SHARP

syslog Overview (pdf)

Linux Event Logging for Enterprise-Class Systems (Open Source)

IPSentry - Alert - Syslog Message

LogController

newsyslog

The NewSyslog Project

Using newsyslog to rotate files containing logging messages on systems running Solaris 2.x

System Log Rotation Service

A shell script for rotating system logs (Spinlogs)

Trimlog

WatchLog (Open Source)

Checking Your System Logs with awk

checksyslog

Remote Syslog with MySQL and PHP

UNIX/Linux local audit tool

Auditing the security of an existing Solaris system can be time-consuming, and often requires on-site visits.

Snare Agent

A GPL'ed library for RFC 3195 syslog

LogWatch

Logwatch is a customizable log analysis system. Logwatch parses through your system's logs for a given period of time and creates a report analyzing areas that you specify, in as much detail as you require. Logwatch is easy to use and will work right out of the package on most systems.

Inspecting the logs produced by the Apache Web server

Profiling LAMP Applications with Apache's Blackbox Logs

Log handle

SMA - Sendmail log analyser

Performance Tuning and Monitoring

HOW TO: Configure ODBC Logging in IIS (MS KB 245243)

How To Enable IIS Logging Site Activity in Windows 2000 (MS KB 300390)

HOW TO: Configure Web Site Logging in Windows Server 2003 (MS KB 324279)

Custom Logging Modules

Maximising IIS logging

How To Use SQL Server to Analyze Web Logs (MS KB 296085)

Snare Agent for IIS Servers

In-Depth IIS Logging

Remote monitor IIS log (pdf)

Sample ASP Code May be Used to View Unsecured Server Files (MS KB 232449)

IIS 4.0 ships with a set of sample files to help web developers learn about Active Server Pages. (txt)

Showcode.asp - A lesson in Internet Security  

Default permissions and user rights for IIS 6.0 (MS KB 812614)

UrlScan Security Tool

Device Specific syslog Configurations

Firewall Logging & Monitoring

Tutorials and quick guides on how to configure devices to report via syslog

Protomatter Free Software

Robust event logging with Syslog

Java

Logging Services Project @ Apache

ActiveLogger

Perl

EventLog module contained in the Perl libwin32 distribution parses

Logfile::Rotate - perl module

PHP

Python

TCLSyslog

Scansyslog - Uses code and ideas from "Tthe Practice of Programming" to look for a large number of semi-static patterns in system logs.

ReportGen Log Reporter

The most popular logfile analyser in the world

Report Magic for Analyser

fwlogwatch

A Utility for Monitoring IPTables Logs and Reporting Port Scans - ScanAlert

WallFire: wflogs

NTLast

Cybersafe Centrax Log Analyst Named Essential Microsoft Windows 2000 Security Utility

Log Parsers (Generic)

Data Correlation

Sample Log Files

Intrusion Signatures from Logs

Messages that Made Us Laugh

Message Dictionaries

ftpd

named reporter

Anteater

BMS generates statistics from your sendmail logs of rejected mail

sm.logger.pl : A Perl script that produces different details from a sendmail log

smtpstats: Brian Beecher's shell script that produces SMTP summaries based on sendmail logs.