<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
<title>Anton Chuvakin on O&apos;Reilly Broadcast</title>
<link rel="alternate" type="text/html" href="http://broadcast.oreilly.com/" />
<link rel="self" type="application/atom+xml" href="http://broadcast.oreilly.com/atom.xml" />
<id>tag:broadcast.oreilly.com,2008-08-07://53</id>
<updated>2010-11-05T17:57:28Z</updated>

<generator uri="http://www.sixapart.com/movabletype/">Movable Type Pro 4.21-en</generator>

<entry>
<title>Log Management Tool Selection Checklist Out</title>
<link rel="alternate" type="text/html" href="http://broadcast.oreilly.com/2010/11/log-management-tool-selection.html" />
<id>tag:broadcast.oreilly.com,2010://53.43284</id>

<published>2010-11-05T17:57:28Z</published>
<updated>2010-11-05T17:57:28Z</updated>

<summary><![CDATA[Knowing how much people love IT-security related checklists, here is one more: a checklist for comparing log management tools.&nbsp;It is being released at the new log management related site, Log Management Central (subscribe to RSS, follow on Twitter). The announcement...]]></summary>
<author>
<name>Anton Chuvakin</name>
<uri>http://www.chuvakin.org</uri>
</author>

<category term="checklist" label="checklist" scheme="http://www.sixapart.com/ns/types#tag" />
<category term="loganalysis" label="log analysis" scheme="http://www.sixapart.com/ns/types#tag" />
<category term="logmanagement" label="log management" scheme="http://www.sixapart.com/ns/types#tag" />
<category term="logreview" label="log review" scheme="http://www.sixapart.com/ns/types#tag" />
<category term="logging" label="logging" scheme="http://www.sixapart.com/ns/types#tag" />
<category term="logs" label="logs" scheme="http://www.sixapart.com/ns/types#tag" />

<content type="html" xml:lang="en" xml:base="http://broadcast.oreilly.com/">
<![CDATA[Knowing how much people love IT-security related checklists, here is one more: a checklist for comparing log management tools.&nbsp;It is being released at the new log management related site, Log Management Central (subscribe to RSS, follow on Twitter). The announcement...]]>
</content>
</entry>

<entry>
<title>Fun Project Honeynet Log Challenge: Log Mysteries</title>
<link rel="alternate" type="text/html" href="http://broadcast.oreilly.com/2010/09/fun-project-honeynet-log-chall.html" />
<id>tag:broadcast.oreilly.com,2010://53.42835</id>

<published>2010-09-01T18:24:13Z</published>
<updated>2010-09-01T18:24:13Z</updated>

<summary>Project Honeynet just released its latest Forensic Challenge 5 - Log Mysteries. It is based on logs from a compromised virtual server and requires quite a bit of digging through messy log data.</summary>
<author>
<name>Anton Chuvakin</name>
<uri>http://www.chuvakin.org</uri>
</author>

<category term="loganalysis" label="log analysis" scheme="http://www.sixapart.com/ns/types#tag" />
<category term="logging" label="logging" scheme="http://www.sixapart.com/ns/types#tag" />
<category term="logs" label="logs" scheme="http://www.sixapart.com/ns/types#tag" />
<category term="projecthoneynet" label="project honeynet" scheme="http://www.sixapart.com/ns/types#tag" />

<content type="html" xml:lang="en" xml:base="http://broadcast.oreilly.com/">
Project Honeynet just released its latest Forensic Challenge 5 - Log Mysteries. It is based on logs from a compromised virtual server and requires quite a bit of digging through messy log data.
</content>
</entry>

<entry>
<title>Most Useful Reports Based On Log Data?</title>
<link rel="alternate" type="text/html" href="http://broadcast.oreilly.com/2010/07/most-useful-reports-based-on-l.html" />
<id>tag:broadcast.oreilly.com,2010://53.40258</id>

<published>2010-07-14T23:32:48Z</published>
<updated>2010-07-14T23:32:48Z</updated>

<summary>Help define the most useful reports from log data.</summary>
<author>
<name>Anton Chuvakin</name>
<uri>http://www.chuvakin.org</uri>
</author>

<category term="loganalysis" label="log analysis" scheme="http://www.sixapart.com/ns/types#tag" />
<category term="logmanagement" label="log management" scheme="http://www.sixapart.com/ns/types#tag" />
<category term="logging" label="logging" scheme="http://www.sixapart.com/ns/types#tag" />
<category term="logs" label="logs" scheme="http://www.sixapart.com/ns/types#tag" />
<category term="security" label="security" scheme="http://www.sixapart.com/ns/types#tag" />
<category term="systemadministration" label="system administration" scheme="http://www.sixapart.com/ns/types#tag" />

<content type="html" xml:lang="en" xml:base="http://broadcast.oreilly.com/">
Help define the most useful reports from log data.
</content>
</entry>

<entry>
<title>Simple Log Review Checklist Released!</title>
<link rel="alternate" type="text/html" href="http://broadcast.oreilly.com/2010/03/simple-log-review-checklist-re.html" />
<id>tag:broadcast.oreilly.com,2010://53.39299</id>

<published>2010-03-09T11:03:04Z</published>
<updated>2010-03-09T11:03:04Z</updated>

<summary>The log cheat sheet presents a checklist for reviewing critical system, network and security logs when responding to a security incident. It can also be used for routine periodic log review. It was authored by Dr. Anton Chuvakin and Lenny Zeltser</summary>
<author>
<name>Anton Chuvakin</name>
<uri>http://www.chuvakin.org</uri>
</author>

<category term="chuvakin" label="chuvakin" scheme="http://www.sixapart.com/ns/types#tag" />
<category term="incidentresponse" label="incident response" scheme="http://www.sixapart.com/ns/types#tag" />
<category term="logmanagement" label="log management" scheme="http://www.sixapart.com/ns/types#tag" />
<category term="logreview" label="log review" scheme="http://www.sixapart.com/ns/types#tag" />
<category term="logging" label="logging" scheme="http://www.sixapart.com/ns/types#tag" />
<category term="logs" label="logs" scheme="http://www.sixapart.com/ns/types#tag" />
<category term="security" label="security" scheme="http://www.sixapart.com/ns/types#tag" />

<content type="html" xml:lang="en" xml:base="http://broadcast.oreilly.com/">
The log cheat sheet presents a checklist for reviewing critical system, network and security logs when responding to a security incident. It can also be used for routine periodic log review. It was authored by Dr. Anton Chuvakin and Lenny Zeltser
</content>
</entry>

<entry>
<title>Top Log FAIL</title>
<link rel="alternate" type="text/html" href="http://broadcast.oreilly.com/2009/10/top-log-fail.html" />
<id>tag:broadcast.oreilly.com,2009://53.38338</id>

<published>2009-10-29T11:55:54Z</published>
<updated>2009-10-29T11:55:54Z</updated>

<summary>A recent Wal-Mart intrusion story inspired me to summarize the most egregious, reckless, painful, negligent, sad, idiotic examples of failures with logs and logging - &quot;Top Log FAIL.&quot;  I am pretty sure that esteemed readers of SysAdmin Blog would never, ever do anything of that sort. </summary>
<author>
<name>Anton Chuvakin</name>
<uri>http://www.chuvakin.org</uri>
</author>

<category term="chuvakin" label="chuvakin" scheme="http://www.sixapart.com/ns/types#tag" />
<category term="fail" label="FAIL" scheme="http://www.sixapart.com/ns/types#tag" />
<category term="failures" label="failures" scheme="http://www.sixapart.com/ns/types#tag" />
<category term="logreview" label="log review" scheme="http://www.sixapart.com/ns/types#tag" />
<category term="logging" label="logging" scheme="http://www.sixapart.com/ns/types#tag" />
<category term="logs" label="logs" scheme="http://www.sixapart.com/ns/types#tag" />
<category term="systemadministration" label="system administration" scheme="http://www.sixapart.com/ns/types#tag" />

<content type="html" xml:lang="en" xml:base="http://broadcast.oreilly.com/">
A recent Wal-Mart intrusion story inspired me to summarize the most egregious, reckless, painful, negligent, sad, idiotic examples of failures with logs and logging - &quot;Top Log FAIL.&quot;  I am pretty sure that esteemed readers of SysAdmin Blog would never, ever do anything of that sort. 
</content>
</entry>

<entry>
<title>Review of &quot;Beautiful Security&quot; Book</title>
<link rel="alternate" type="text/html" href="http://broadcast.oreilly.com/2009/06/review-of-beautiful-security-b.html" />
<id>tag:broadcast.oreilly.com,2009://53.37255</id>

<published>2009-06-22T14:52:51Z</published>
<updated>2009-06-22T14:52:51Z</updated>

<summary>Beautiful Security from O&apos;Reilly, which I just finished reading, is truly an awesome book. Now, I will probably have a high opinion of my own chapter (&quot;Beautiful Log Handling&quot;) since it took some work (eh... and one near-complete rewrite) to...</summary>
<author>
<name>Anton Chuvakin</name>
<uri>http://www.chuvakin.org</uri>
</author>

<category term="book" label="book" scheme="http://www.sixapart.com/ns/types#tag" />
<category term="review" label="review" scheme="http://www.sixapart.com/ns/types#tag" />

<content type="html" xml:lang="en" xml:base="http://broadcast.oreilly.com/">
Beautiful Security from O&apos;Reilly, which I just finished reading, is truly an awesome book. Now, I will probably have a high opinion of my own chapter (&quot;Beautiful Log Handling&quot;) since it took some work (eh... and one near-complete rewrite) to...
</content>
</entry>

</feed> 
