Re: Log Monitoring

2014-08-07 Thread G.W. Haywood
Hi there, On Thu, 7 Aug 2014, Davis, Donald W wrote: I am looking for scripts that can be used to parse and monitor the DNS logs for suspicious activity. If Nagios didn't exist, I'd have to invent it: http://exchange.nagios.org/directory/Plugins/Network-Protocols/DNS http://www.nagios.com/so

Log Monitoring

2014-08-07 Thread Davis, Donald W
I am looking for scripts that can be used to parse and monitor the DNS logs for suspicious activity. I have enabled full logging and am currently using the DNSAnomalyDetection script written by Dr. Johannes Ulrich. This script gives me the daily top 10 requests based on the query logs. Does any