3 ms·
Working with SIEMS a lot, I agree it needs a serious revision. 1. Define an encryption standard, both symmetric and asymmetric (to prevent log tampering). 2. D
by TenOhms 10y ago
Working with SIEMS a lot, I agree it needs a serious revision.
1. Define an encryption standard, both symmetric and asymmetric (to prevent log tampering).
2. Define a compression standard, with scheduling options similar to cron jobs but defined in syslog.conf.
3. Overhaul the facility field, define some generic ones like "Auth", "Audit", "Kernel" etc and don't hardcode any numeric mappings. Article covers this well.
4. Make CEF the standard format for writing logs to disk or forwarding to other devices. All modern applications and kernels should be writing their logs in CEF format.