YOUR FEEDBACK
Verizon Becomes a Counter-Android Linux Convert
JNels wrote: Hey - Jeffrey Nelson here at Verizon Wireless. Not a bit of ...
SOA World Conference
Virtualization Conference
$200 Savings Expire May 16, 2008... – Register Today!


2007 West
GOLD SPONSORS:
Active Endpoints
Your SOA Needs BPEL for Orchestration
BEA
Virtualized SOA: Adaptive Infrastructure for Demanding Applications
Nexaweb
Overcoming Bandwidth Challenges with Nexaweb
TIBCO
What is Service Virtualization?
SILVER SPONSORS:
WSO2
Using Web Services Technologies and FOSS Solutions
Click For 2007 East
Event Webcasts

2008 East
PLATINUM SPONSORS:
Appcelerator
Think Fast: Accelerate AJAX Development with Appcelerator
GOLD SPONSORS:
DreamFace Interactive
The Ultimate Framework for Creating Personalized Web 2.0 Mashups
ICEsoft
AJAX and Social Computing for the Enterprise
Kaazing
Enterprise Comet: Real–Time, Real–Time, or Real–Time Web 2.0?
Nexaweb
Now Playing: Desktop Apps in the Browser!
Sun
jMaki as an AJAX Mashup Framework
POWER PANELS:
The Business Value
of RIAs
What Lies Beyond AJAX?
KEYNOTES:
Douglas Crockford
Can We Fix the Web?
Anthony Franco
2008: The Year of the RIA
Click For 2007 Event Webcasts
SYS-CON.TV
TOP LINKS YOU MUST CLICK ON


Open Source Project LASSO for Log Management
Open source software for collecting Windows event logs

Digg This!

Recently, I had the pleasure of speaking with Anton Chuvakin, Director of Product Management at LogLogic. We had an interesting discussion about log management and the open source project he's involved in that collects Windows event logs. Here's an overview of our chat.

Drowning in logs is all too common nowadays when organizations are struggling with a combination of operational, security, and compliance requirements. A typical organization will have logs from a wide array of log sources such as server operating systems (Unix and Windows), desktops, mainframes, network gear such as routers and switches, web proxies, security gear such as network IDS, IPS or anti-virus tools, Web, e-mail, and DNS server software as well as enterprise applications.

Large organizations typically have tens of thousands of servers generating log files. The challenge for IT is how an enterprise can efficiently collect logs from all these servers without losing any data. In fact, almost 30% of all enterprise data is log data. Owing to compliance requirements from regulations like Sarbanes-Oxley and PCI, the archived log data must be stored. A single organization can easily be required to store hundreds of terabytes of log data. How IT manages this large set of data continues to be a challenge for enterprises, regardless of size.

Log Management and Intelligence is an approach to dealing with large volumes of computer-generated log messages (also known as audit records, audit trails, event logs, etc.), which consists of log collection, centralized aggregation, long-term retention, log analysis (in real-time and in bulk after storage) as well as sharing the information with the relevant parties across the organization. Such analysis is usually done for security, operational (such as system or network administration), or regulatory compliance.

Effectively analyzing large volumes of diverse logs is a challenge. From huge log volumes - often reaching hundreds of gigabytes of data a day for a large organization - to log format diversity, obstacles in dealing with log data confounds IT daily. Couple that with undocumented proprietary log formats that often hinder analysis and the presence of false log records found in certain logs, such as intrusion detection logs, and the situation becomes more complex.

To unravel the complexity, tools to handle log collection and analysis are sometimes built by users, assembled from various open source components or acquired from commercial vendors in the form of LMI or Log Management and Intelligence solutions. So far, the open source community hasn't been able to come up with a single tool to deal with most log challenges that confront IT. But there are some promising contenders.

Moreover, the open source community has been pretty effective in building pieces of log management infrastructure. Syslog-NG enables log collection from Unix servers and network devices, serving as a better replacement for standard syslog daemons than is typically provided by operating system vendors as a primary example of open source excellence., There are also a huge number of simple scripts and small programs such as logwatch, logsentry, and fwanalog that were written by the open source community over the years to handle specific logs or a particular slice of a log puzzle. At times it seems that it was easier for some people to create their own script instead of looking for one online. However, most of these tools focused on Unix and Linux platforms and largely ignored Windows-based systems.

One of the recent open source solutions that enables a critical part of log management is Project LASSO, a Windows-based open source software designed to collect Windows event logs, including custom application logs, and provide for the central collection and transport of Windows log data via TCP syslog to any syslog-NG compatible log receivers. Before Project LASSO incorporating Windows server and workstation logs in an overall log management process was extremely onerous. One had to use agents installed on every single Windows system to collect the logs or be stuck with super-expensive proprietary solutions. And deploying agents on every system is one of the most dreaded tasks in all of enterprise IT.

Open source tools such as syslog-ng existed for years to simplify log management for Unix and Linux as well as network devices that support syslog (such as Cisco routers and firewalls), but the Windows part of the world was largely excluded because binary Windows event logs aren't syslog. Project LASSO bridges this gap, allowing remote Windows log collection without agents, as well being deployed as an agent on each server, if needed. LASSO enables the inclusion of logs in log management systems, such as the one by LASSO's sponsor LogLogic or other companies.

Overall, Project LASSO enables users to connect the dots by allowing central collection and analysis of Windows event logs with the same ease that they are used to with Unix and Linux. After the data is collected by LASSO, users can use report and search features to review and analyze logs across all the systems in an enterprise: Windows, Unix, network systems, applications, etc. Moreover, LASSO greatly reduces the impact on monitored servers in terms of storage and processing, as well being able to capture application-specific and custom Windows event logs.

Using LASSO, IT can gain invaluable insight into its network. For example, a query for an account holder can be run across all the systems in an enterprise, identifying the files or applications that he or she touched. Such capability is critical for compliance, as well as for incident response and forensics.

Log Management is increasingly making its way onto the IT agenda. Today, a simple Google search of "log management" drives this home with over 240 million hits - and it's growing daily. As more organizations move toward implementing policies for compliance, log management systems have taken on a vital role. LMI's greatest value lies not only in the improvements it creates in automating compliance and providing forensics, but there are great benefits to be found in ensuring operational efficiency by giving IT visibility into the details of what has happened on every system in its network. As Log Management and Intelligence matures, the open source tools that intersect with log files will surely continue to evolve and mature.

About Jon Walker
Jon Walker serves as CTO of Versora, an ISV providing Microsoft to Linux migration software. Mr. Walker recently has co-authored 2 whitepapers with Novell titled Migrating from IS Web Servers to Apache SUSE LINUX Enterprise Server 9.0 and Migrating File and Print Servers from Windows to SUSE LINUX Enterprise Server 9. Prior to Versora, Mr. Walker was CTO/VP of Engineering for Miramar Systems. Software developed under his direction at Miramar has been deployed to over 20 million computers worldwide. Mr. Walker has also served as senior technologist for Nortel and Xing Technology (now Real Networks).

Michael S. wrote: Lasso is indeed a very good tool (I really appreciate the agentless capabilities), but the open source community has not forgotten Windows at all. If you look at solutions like OSSEC, you will see that it provides a cross-platform solution for centralized log collection and analysis, all open source and well supported.
read & respond »
Anton Chuvakin wrote: Please correct the spelling of my name!!!
read & respond »
ENTERPRISE OPEN SOURCE MAGAZINE LATEST STORIES . . .
Open-Xchange to Deliver Collaboration Solution Integrated With Parallels Virtualization
Open-Xchange and Parallels are integrating Open-Xchange open source email and collaboration software with Parallels technology to deliver a cost-effective, enterprise-class alternative to commercial email and collaboration products at a competitive price. The products, which will be fu
3rd International Virtualization Conference & Expo: Themes & Topics
From Application Virtualization to Xen, a round-up of the virtualization themes & topics being discussed in NYC June 23-24, 2008 by the world-class speaker faculty at the 3rd International Virtualization Conference & Expo being held by SYS-CON Events in The Roosevelt Hotel, in midtown
Open Source Penetration and Use in SOA Deployments
Open source has made significant inroads into middleware deployments in the enterprise. More and more, open source is being used to deliver the benefits of SOA and open source to the enterprise. There are many custom Enterprise Service Bus deployments waiting to be upgraded to a simple
JavaOne 2008: Uncommon Java Bugs
Any large Java source base can have insidious and subtle bugs. Every experienced Java programmer knows that finding and fixing these bugs can be difficult and costly. Fortunately, there are a large number of free open source Java tools available that can be used to find and fix defects
OpenOffice 3.0 Goes to Public Beta
OpenOffice.org is publicly beta testing OpenOffice 3.0, which is not recommended for production use. General release is expected in September. Aside from cosmetics, it will support the upcoming OpenDocument Format 1.2 and is capable of opening Office 2007 and 2008 for Mac OS X files.
JavaOne 2008: Sun Challenges Linux
Sun's mule train has finally pulled into Indiana after three years on the road. Indiana is the Linux-friendly Fedora-like OpenSolaris project meant to move the Solaris-shy Linux community off Linux and on to Solaris tempted by Solaris widgetry like the highly scalable, rollback-easy, 1
SUBSCRIBE TO THE WORLD'S MOST POWERFUL NEWSLETTERS
SUBSCRIBE TO OUR RSS FEEDS & GET YOUR SYS-CON NEWS LIVE!
Click to Add our RSS Feeds to the Service of Your Choice:
Google Reader or Homepage Add to My Yahoo! Subscribe with Bloglines Subscribe in NewsGator Online
myFeedster Add to My AOL Subscribe in Rojo Add 'Hugg' to Newsburst from CNET News.com Kinja Digest View Additional SYS-CON Feeds
Publish Your Article! Please send it to editorial(at)sys-con.com!

Advertise on this site! Contact advertising(at)sys-con.com! 201 802-3021

SYS-CON FEATURED WHITEPAPERS

ADS BY GOOGLE