listen to your_data!

12

Upload: mohammed-almaraghy

Post on 28-Nov-2014

808 views

Category:

Technology


2 download

DESCRIPTION

Centralized Log Server On RedHat Enterprise Linux 6!

TRANSCRIPT

Page 1: Listen to your_data!
Page 2: Listen to your_data!

Overview

● What is “Centralized Log Server” ?

● Why we need Centralized Log Server ?

● Importance of using Centralized Log Server

● Easily of getting logs!

● SPLUNK!!!

● DEMO

Page 3: Listen to your_data!

What is “Centralized Log Server” ?

Page 4: Listen to your_data!

What is “Centralized Log Server” ?

It is a normal workstation with free RedHat Linux 6 Installed without any additional software installed

It uses basic Linux Knowledge to collect the logs from all clients through TCP & UDP connections to one centralized machine

Page 5: Listen to your_data!

Why we need Centralized Log Server ?

Page 6: Listen to your_data!

Importance of Using C. Log Server

- Collect security logs from all workstations and servers to one machine

- Monitor the network & respond to attacks

- Show password changes for all users

- Show when ANY workstation reboot or shutdown

Page 7: Listen to your_data!

Easily of getting logs! “/var/log/”

User “root” changed his password:Mar 23 14:57:20 localhost passwd: pam_unix(passwd:chauthtok): password changed for root

Local Authentication Failure: Mar 23 14:58:46 localhost login: pam_unix(login:auth): authentication failure; logname=LOGIN uid=0 euid=0 tty=tty3 ruser= rhost= user=root

Poweroff or Reboot:Mar 22 15:58:01 localhost init: tty (/dev/tty2) main process (1896) killed by TERM signal

SSH Authentication Failure:Mar 18 01:13:18 rhel5.vmz sshd[2793]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=10.0.0.2 user=root

Page 8: Listen to your_data!

SPLUNK!!

- Graphical User Interface application to view system logs

- Free & Open Source project

-Quick Search, saved search, alerting,scheduling, and dashboard creation

- Make graphical reports

Page 9: Listen to your_data!
Page 10: Listen to your_data!
Page 11: Listen to your_data!

Any Questions ?!!

Page 12: Listen to your_data!

THANK YOU !

By: Mohammed Al­Maraghy

RedHat Certified Engineer

            Twitter: @MohammedMaraghy

[email protected]