Monitoring logs with Logcheck and Logsurfer

Log Rider

Article from Issue 139/2012

Logfiles contain records of what happens on a Linux system and the services it runs. Tools like Logcheck and Logsurfer filter out the most important events for the administrator, and they can even trigger an appropriate reaction automatically.

Most sys admins rely on logfiles as an important source of security and troubleshooting information. System information typically resides in several different logfiles on every computer, and dozens or even hundreds of computers might fall within the oversight of a single IT specialist. In this setting, the ancient technique of combing through logfiles manually to look for suspicious information has long lost its shine. Many admins use text-filtering tools such as grep to look for specific warnings or events. Grep and its text search counterparts still play an important role on the network, but if you’re looking for a little relief from the tedious task of monitoring logfiles, you might want to try a log analysis tool.

Buy this article as PDF

Express-Checkout as PDF
Price $2.95
(incl. VAT)

Buy Linux Magazine

Get it on Google Play

US / Canada

Get it on Google Play

UK / Australia

Related content

  • Five lean tools for monitoring logfiles

    Anyone wanting to monitor logfiles could use one of the big dogs like Nagios or Icinga. However, lightweight alternatives can also sniff out threats and take much less time to set up. We put five of these little guard dogs to the test.

  • Host-Based IDS

    A host-based intrusion detection system is a simple but powerful tool for finding traces of an attacker's footprint.

  • Email Encryption with Zeyple

    IT specialists often rely on automatic notification for status messages and logfiles by email. A Python script named Zeyple uses GPG to protect potentially sensitive messages against unauthorized viewing.

comments powered by Disqus
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs
Subscribe to our ADMIN Newsletters

Support Our Work

Linux Magazine content is made possible with support from readers like you. Please consider contributing when you’ve found an article to be beneficial.

Learn More