Attach our central syslog server as data source for our instance of Warden/Mentat
There are lots of interesting data just lying around on the hard drives.
Updated by Pavel Kácha 5 months ago
- Status changed from New to Closed
- Assignee deleted (
Does not belong into Mentat, however:
Pavel Kácha wrote in #note-3:
- SSH bruteforces
Now getting off with more data on central logserver.
- Migrate spam fail2ban
- Chat with DNS Master
No interesting info in DNS logs (would need more detailed logging, which is unfeasible performance-wise), however Passive DNS may get up to the task.