|
What is PIX Logging Architecture? The PIX Logging Architecture [PLA] is a free and open-source project allowing for correlation of Cisco PIX, Cisco FWSM and Cisco ASA Firewall Traffic, IDS and Informational Logs. PIX Log message parsing is performed through the use of the PLA parsing module or PLA Msyslogd module. Centralization of the logs is provided using a MySQL database, supported by a Web-based frontend for Log Viewing, Searching, and Event Management. PIX Logging Architecture is completely coded in the Perl programming language, and uses various Perl modules including Perl::DBI and Perl::CGI. What's New in PIX Logging Architecture version 2.0? PIX Logging Architecture v2.x is a new major release of the PLA software and features the following:
The PIX Logging Architecture Database has been redesigned for more efficient use of resources including faster loading of pages, speeding up searches and cross-table indexing. Several new tables have been added and some existing tables have been altered to enable new features to be supported. Extended Parsing Module The PIX Logging Architecture parsing module, which is responsible for extracting the necessary fields from the PIX system log messages, has been extended to gather new information including, but not limited to, Translations (Xlate's), Informative Log Messages (i.e. PIX Failover, PIX VPN Establishment, PIX Interface Up/Down, PIX PPPoE VPDN establishment and the like). All the parsing information needed by the PLA Parsing Daemon (pla_parsed) in order to extract data from the logs is now stored in the database, allowing for easy updates of the supported log messages without having to replace the parsing scripts. Moreover, the PLA Parsing Daemon runs as a daemonized Perl process in the background and reads straight and in quasi real-time from the system log files, so no more need to create crontab jobs like before and having to restart syslogd all the time. Parse-Time Filtering With the PIX Logging Architecture v2.00 version comes the ability to perform parse-time filtering. Parse-time filtering allows you to use the PLA web interface to define traffic which you do not wish you log (i.e. between specific IP pairs and ports, on specific protocols, on specific firewalls). The PLA Parse Daemon (pla_parsed) then checks the incoming firewall logs and will exclude any traffic which matches the parse-time filters. Using these parse filters allows to keep tabs on the database size and prevents you from having to log all data. Security Dashboard The PIX Logging Architecture front-end has been equipped with a "Security Dashboard" feature, allowing for the Top Dropped & Accepted Sources, Destinations and Services to be listed. Additionally a set of graphs provides a statistical analysis of the drops and accepts, protocol redistribution and cumulative amount of logged data over a 24-hour, 7-day, 30-day and 12 month time period on a per-firewall basis. Extended Search Parameters The traffic and IDS log search capabilities within PIX Logging Architecture have been extended to allow for more granular searching including searching based on protocol, more accurate time ranges and exact PIX log or IDS message names, allowing for the results to be refined and in turn decrease the time needed to display the results. PIX Logging Architecture v2.00 also introduces the ability to search the informational (audit) logs. Information log searches such as SSH logins, username searches, configuration change searches and the like can now be carried out easily. Optimized Traffic/IDS Log Display The extraction of additional data from the PIX logs has allowed PIX Logging Architecture to optimize it's Traffic Logs and IDS Logs displaying. It's now possible to perform host name resolutions on the display of these pages. Additional information gathered allows address translations (PAT/NAT Xlate's) to now be displayed as part of a unique PIX logged event. Redesign of the displayed logging information and introduction of icons creates a more user-friendly look and feel to the PIX Logging Architecture front-end. Information Logs and User-defined Queries Two new tabs have been introduced into the PIX Logging Architecture version 2.x dashboard. Traffic Log Filtering and Descriptions Two new functions have been introduced in relation to PIX Traffic Logs. Sorting and Paging All PIX Logging Architecture pages which provide log listings (Traffic Logs, IDS Logs, Informational Logs, Queries as well as all search pages) are now equipped with a sorting and paging function, limiting the number of records (default: 50 records) being displayed at once and improving the efficiency at which logs can be analyzed by being able to sort the listing on any displayed field in and ascending or descending manner. The current paging feature allows for either 50, 100, 250, 500 or 1000 logs to be displayed per page, providing "Next", "Previous" and "Refresh" buttons for easy navigation between the different views. PLA Database Log Purging A configuration option has been added to allow for log purging from within the PIX Logging Architecture web-based front end. Several purging policies have been predefined and can be chosen and applied to either Traffic, IDS or Informational Logs. Log purging allows to clear old entries easily without having to manually edit the database. PLA Configuration Tab A PIX Logging Architecture Configuration tab has been added to the PIX Logging Architecture version 2.0 front-end. This configuration tab allows the for configuration of User-defined Queries, Traffic Log Display Filtering, Traffic Log Descriptions and Event/Incident Management. The PLA configuration interface allows for creating, searching and editing the different configurable options of PIX Logging Architecture version 2.0. Screenshots PIX Logging Architecture v2.00 in action:
Software Release / Downloads
PIX Logging Architecture v2.00 has been released and is available for download. Click here to download PIX Logging Architecture v2.00. Note: Please note that the PIX Logging Architecture version 1.x release is no longer maintained nor supported. Discussion Forum *NEW* - PIX Logging Architecture v2.00 Discussion Forum Through the PIX Logging Architecture v2.00 Discussion Forum, available on http://forum.logging-architecture.net/, you can get community support on any PIX Logging Architecture related questions as well as share experiences, knowledge and tweaks on PIX Logging Architecture. Mailing Lists Several Mailing Lists have been set up so that you can stay up to date with the latest announcements, feature requests, support information and bug tracking.
Contact Information If you have any questions, thoughts, comments or ideas to share you can contact me either by email or by dropping me a message on my web site: Support The PLA Project! What makes free open source software great and keeps it innovative is the fact that many people around the world have access to the software and have the opportunity to test it and use it as much as they want! And PIX Logging Architecture is no different! People can run it on their own networks and test it with their own system log data. What's even greater is that the more people test the PLA project the more feedback I'll get about new features to add as well as improvements to current features. So if you like the PLA project and wanna help us make a difference out here we would really appreciate you linking to the PIX Logging Architecture project's web site so that more people know about this project and can help improve it! One way of doing this is by putting the following code on your website which will display the small (120x18) banner shown below. <a href="http://www.logging-architecture.net"><img src="http://www.logging-architecture.net/pla_banner_small.jpg" alt="PIX Logging Architecture" border="0"></a> If you don't have a web site and you feel like helping us out, you can help us come up with new and useful features for the PIX Logging Architecture by dropping me a mail at kris@logging-architecture.net! Keep The PLA Project Running! PIX Logging Architecture is a software which is being provided for free and can be used without any obligations or monetary compensation. Nevertheless, costs (such as hosting as well as hardware investments) are involved in running the PIX Logging Architecture project and keeping it as up to date as possible and support the latest software and hardware technologies which we try to maintain through the means of donations and sponsored ads clicks. Your click to our sponsors as well as your donations to this project can make the difference in keeping this site and it's project up and running! PIX Logging Architecture Banner: Last Update: 22-Mar-2008 |
|