Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 1 Mar 2002 11:07:07 +0100 (CET)
From:      Peter Ross <peter.ross@alumni.tu-berlin.de>
To:        Christian Gielstrup <lists@gielstrup.dk>
Cc:        freebsd-security@freebsd.org
Subject:   Re: resolve ipaddr and ports in logs
Message-ID:  <Pine.BSF.4.21.0203011037451.404-100000@sorchen.zrz.tu-berlin.de>
In-Reply-To: <004b01c1c0c6$1b413380$7800000a@gielstrup.dk>

next in thread | previous in thread | raw e-mail | index | archive | help
Hi Christian

> Greetings from Denmark..

Hi, greetings from your southern neighbour in Germany:)

> Is it possible to have the ipaddresses and ports resolved on the rules
> that are logged?
 
I think it isn't a good idea cause it takes too much time and traffic. If
there are Disastrous Name Service (DNS) problems the output may stop. And
you need the logs if you have problems..

Write a script which takes the log file, performs the DNS lookups,
looks in /etc/services and write the resolved addresses and ports to the
output.                                                                 

You need the resolved addresses only if you look over.

Regards
Peter


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.4.21.0203011037451.404-100000>