The logs contained in this document are divided in four categories. The categories are router, firewall, Intrusion Detection Systems (IDS) and miscellaneous. These logs are meet to be used as reference to identify the type of software that generated a log model and if necessary, how they can be interpreted. | A collection of various computer and security logs The logs contained in this document are divided in four categories. The categories are router firewall Intrusion Detection Systems IDS and miscellaneous. These logs are meet to be used as reference to identify the type of software that generated a log model and if necessary how they can be interpreted. Copyright Guy Bruneau 2000-2001. All rights reserved. Router Ascend Cisco Cisco ACL Firewall Gauntlet Raptor IPFilter FreeBSD OpenBSD IPChains Linux ConSeal Firewall Windows ZoneAlarm Windows Cisco PIX SonicWall SOHO Cyberguard EnterNet Check Point FireWall-1 3Com OfficeConnect Internet Firewall 25 Appliance Norton Internet Security 2001 - Family Edition Intrusion Detection Systems Snort Snortsnarf Shadow SecureNet Pro BlackICE Defender ClearICE report BlackICE PortSentry Rainbow Diamond The meaning of various computer and security logs Page 1 of 39 Argus RealSecure RSLog Cisco Secure IDS Pakemon Alert Pakemon Dump Miscellaneous ASCTcpdump TCPLogd UNIX messages Apache access Apache error Ethereal Protolog TCP Protolog UDP Protolog ICMP Windows NT 4 Security log Sniffer Pro Samba NMB Samba SMB Solaris snoop TCPDump TCPDump and DNS TCPDump ICMP and TCP stimulus response IP and TCP IP and UDP IP and ICMP Revision history Guy Bruneau version - 14 February 2001 The meaning of various computer and security logs Page 2 of 39 Router Logs Ascend router Oct 24 01 03 13 ASCEND wan4 tcp 9704 - 9704 40 syn fin pass totcp-1 Oct 24 01 03 13 ASCEND wan4 tcp 9704 - 9704 40 syn fin pass totcp-1 Oct 24 01 04 23 ASCEND wan4 tcp 9704 - 9704 40 syn fin pass totcp-1 Oct 24 01 04 23 ASCEND wan4 tcp 9704 - 9704 40 syn fin pass totcp-1 Ascend Pipeline 130 Firewall Logs breakdown. Read from Left to Right. Traffic Meaning Aug 24 01 03 13 - Date Time