TAILIEUCHUNG - Open Source Security Tools : Practical Guide to Security Applications part 27

Open Source Security Tools : Practical Guide to Security Applications part 27. Few frontline system administrators can afford to spend all day worrying about security. But in this age of widespread virus infections, worms, and digital attacks, no one can afford to neglect network defenses. Written with the harried IT manager in mind, Open Source Security Tools is a practical, hands-on introduction to open source security tools. | Page 239 Thursday June 24 2004 9 54 PM Analysis and Management Tools 239 Table Swatch Log File Options Options Descriptions --examine file Makes Swatch do a complete pass through the indicatedfile. Use this when the file being examined is created anew each time. --read-pipe program Instead of reading a file you can have Swatch read input directly piped from the indicated program. --tail file Reads only the newly added lines in file. This is the default operation for Swatch on log files since new entries are usually appended to the end of an existing file. This is much faster than rereading a whole file every time especially with log files that can get quite big such as Web server logs. Table lists and describes some additional options that you can use to control how Swatch reads the log files. You can only use one of these switches at a time. For example running Swatch with this command . swatch --examine messages --daemon has Swatch search the entire messages file every time it runs rather than just checking for newly added lines. Swatch normally scans the UNIX messages file or if there is no messages file it defaults to the syslog file. Using these switches in Table you could have Swatch look at any log file you want such as the security logs or even an application-specific log file like . The Swatch Configuration File The Swatch configuration file is where all the important settings are. In this file called swatchrc by default you tell the program what to look for in the log files and what to do if that shows up. Two sample swatchrc files are included with the program in the examples directory. The file is for use on a personal workstation and is for server monitoring. Listing shows what the monitor version looks like. Listing The swatchrc Monitor Configuration File Swatch configuration file for constant monitoring Page 240 Thursday June 24 2004 9 54 PM 240 .

TỪ KHÓA LIÊN QUAN
TAILIEUCHUNG - Chia sẻ tài liệu không giới hạn
Địa chỉ : 444 Hoang Hoa Tham, Hanoi, Viet Nam
Website : tailieuchung.com
Email : tailieuchung20@gmail.com
Tailieuchung.com là thư viện tài liệu trực tuyến, nơi chia sẽ trao đổi hàng triệu tài liệu như luận văn đồ án, sách, giáo trình, đề thi.
Chúng tôi không chịu trách nhiệm liên quan đến các vấn đề bản quyền nội dung tài liệu được thành viên tự nguyện đăng tải lên, nếu phát hiện thấy tài liệu xấu hoặc tài liệu có bản quyền xin hãy email cho chúng tôi.
Đã phát hiện trình chặn quảng cáo AdBlock
Trang web này phụ thuộc vào doanh thu từ số lần hiển thị quảng cáo để tồn tại. Vui lòng tắt trình chặn quảng cáo của bạn hoặc tạm dừng tính năng chặn quảng cáo cho trang web này.