标签:des style blog http color os io java ar
http://static.usenix.org/events/lisa10/tech/full_papers/Krizak.pdf
http://sagan.quadrantsec.com/
https://www.openhub.net/p/palantir3
https://github.com/beave/sagan-rules/blob/master/README
http://www.logalyze.com/
http://nxlog.org/
http://baudlabs.com/top-free-and-open-source-log-management-software/
https://isc.sans.edu/diary/SAGAN%3A+An+open-source+event+correlation+system+-+Part+1%3A+Installation/9184
http://www.securitywarriorconsulting.com/logtools/
http://www.opennms.org/wiki/Drools_Correlation_Engine
opennms
http://blog.profitbricks.com/top-47-log-management-tools/
https://www.usenix.org/conference/lisa12/technical-sessions/presentation/lang_david
http://comments.gmane.org/gmane.comp.log.sec.user/1345
Networks create lots of events. Sometimes thousands per minute.
Events can be SNMP traps generated by a server rebooting, syslog messages, Microsoft Windows event logs etc.
How do you know which events are important? The ones telling you something important?
That is where event correlation tools come in handy. You feed all of the events into the tool, as well as a description of the structure of your systems, and its job is to flag up the important ones.
If you want a survey of event correlation techniques and tools, you could do a lot worse than read Andreas Müller’s master’s thesis titledEvent Correlation Engine. It is a few years old, but is still pretty current.
开源日志关联系统 opensource log Correlation
标签:des style blog http color os io java ar
原文地址:http://blog.csdn.net/cnbird2008/article/details/39137483