From the course: Network Forensics

Unlock the full course today

Join today to access over 23,300 courses taught by industry experts.

syslog-ng

syslog-ng

- [Narrator] Syslog-ng is another log management server solution. Just like syslog, it can manage logs on a single host or forward them to a central log server. It's also possible to make it a dedicated log server. Syslog-ng is a newer, open-source project than its predecessor, syslog. NG in syslog-ng stands for next generation. As it's name suggests, it tries to improve syslog with more reliability and features. Syslog-ng's goal is that it does all of what syslog can offer but better, faster and much more. One of the enhancements is it's ability to set up advanced filters for log messages. This function is very useful because there are usually too many logs to store and the filters help you pick and choose what to keep in a more fine-grained way. Another capability to note is processing, meaning Syslog-ng taking an action to further prepare the collected logs. Syslog-ng should be able to handle most of log management tasks if not all. Syslog-ng doesn't come with a standard Ubuntu…

Contents