<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>システム管理な雑記 -- Sleeve notes of a sysadmin -- : Interoperability</title><link>http://msmvps.com/blogs/yamaken/archive/tags/Interoperability/default.aspx</link><description>Tags: Interoperability</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Honeynet Security Console</title><link>http://msmvps.com/blogs/yamaken/archive/2004/05/16/6546.aspx</link><pubDate>Sun, 16 May 2004 23:36:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:6546</guid><dc:creator>kenji</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/yamaken/rsscomments.aspx?PostID=6546</wfw:commentRss><comments>http://msmvps.com/blogs/yamaken/archive/2004/05/16/6546.aspx#comments</comments><description>&lt;p&gt;From &lt;a title="seculogger" href="http://www.7th-angel.net/seculog/" target="_blank"&gt;seculogger&lt;/a&gt;'s &lt;a href="http://www.7th-angel.net/seculog/item/548.html" target="_blank"&gt;blog&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.activeworx.org/programs/hsc/index.htm"&gt;Honeynet Security Console&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;It seems very neat. I decided that I should evaluate this, with &lt;a href="http://project.honeynet.org/tools/sebek/" target="_blank"&gt;sebek!&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=6546" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Misc/default.aspx">Misc</category><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Security+tips/default.aspx">Security tips</category><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Tools/default.aspx">Tools</category><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Interoperability/default.aspx">Interoperability</category><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Windows+management/default.aspx">Windows management</category></item><item><title>SNMP and WMI on Windows: WMIex.MSFT.NET</title><link>http://msmvps.com/blogs/yamaken/archive/2004/04/14/snmp-and-wmi-on-windows-wmiex-msft-net.aspx</link><pubDate>Wed, 14 Apr 2004 04:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:4943</guid><dc:creator>kenji</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/yamaken/rsscomments.aspx?PostID=4943</wfw:commentRss><comments>http://msmvps.com/blogs/yamaken/archive/2004/04/14/snmp-and-wmi-on-windows-wmiex-msft-net.aspx#comments</comments><description>&lt;p&gt;The famous &lt;a href="http://snmpboy.msft.net/" target="_blank"&gt;snmpboy site&lt;/a&gt; has evolved dramatically to handle WMI implementation!&lt;/p&gt;
&lt;p&gt;&lt;a href="http://wmiex.msft.net/" target="_blank"&gt;http://wmiex.msft.net/&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=4943" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Network+Technologies/default.aspx">Network Technologies</category><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Interoperability/default.aspx">Interoperability</category><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Windows+management/default.aspx">Windows management</category></item><item><title>Syslog management on Windows platforms.</title><link>http://msmvps.com/blogs/yamaken/archive/2004/01/29/2193.aspx</link><pubDate>Fri, 30 Jan 2004 05:18:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:2193</guid><dc:creator>kenji</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/yamaken/rsscomments.aspx?PostID=2193</wfw:commentRss><comments>http://msmvps.com/blogs/yamaken/archive/2004/01/29/2193.aspx#comments</comments><description>&lt;p&gt;
Do you know &lt;a href="http://www.winsyslog.com/"&gt;WinSyslog&lt;/a&gt; from &lt;a href="http://www.adiscon.com/"&gt;Adiscon&lt;/a&gt;? It is so cool a tool for us system operators/administrators.&lt;br /&gt;
Check it out at: &lt;a href="http://www.adiscon.com/"&gt;http://www.adiscon.com/&lt;/a&gt;&lt;br /&gt;
(For Japanese: &lt;a href="http://adiscon.port139.co.jp/"&gt;http://adiscon.port139.co.jp/&lt;/a&gt;)&lt;br /&gt;
This tool is so cool, as it allows you to consolidate all the standard error/log messages to one server. With MSSQL you can even display the messages via IIS 4/5. Merging Syslog, SNMP, and Windows Event logs are critical for system admins, to whom we can say this tool is the very solution for managing system health in general. &lt;br /&gt;
You can merge SNMP with syslog, using either the latest version of WinSyslog, or with Kiwi Syslog Daemon (&lt;a href="http://www.kiwisyslog.com"&gt;http://www.kiwisyslog.com&lt;/a&gt;).&lt;br /&gt;

You can merge Windows event logs with the following tools:&lt;br /&gt;
&lt;/p&gt;&lt;blockquote&gt;
&lt;p align="left"&gt;1. Event Reporter from Adiscon&lt;/p&gt;
&lt;p align="left"&gt;2. Event logs to syslog utility from Purdue University.&lt;/p&gt;
&lt;p align="left"&gt;3. ntsyslog service tool from SourceForge&lt;/p&gt;
&lt;p align="left"&gt;cf. I found a localised version of ntsyslog in Vector or Mado-no-mori, which uses EUC-JP for Japanese. If you have already deployed Linux- or *NIX-based solution for the consolidation of logs, this client is just-fit, it seems.&lt;/p&gt;&lt;/blockquote&gt;
Note: there are other tools in the world to facilitate this function. According to Kawabata-san (&lt;a href="http://www.kawabata.com/"&gt;http://www.kawabata.com/&lt;/a&gt;), you can even write up the tool that just-fits to your need. ;-)&lt;br /&gt;
&lt;p&gt;***System Requirements:&lt;/p&gt;
A. System: See the URLs above&lt;br /&gt;
B. Human:&lt;br /&gt;
&lt;blockquote dir="ltr" style="MARGIN-RIGHT: 0px"&gt;
&lt;p align="left"&gt;B-1. Knowledge of syslog (unix and network devices you use.)&lt;/p&gt;
&lt;p align="left"&gt;B-2. Ability or Experience of manually parsing eventlogs on Windows&lt;/p&gt;
&lt;p align="left"&gt;B-3. Ability to configure network devices to emit logs, if you think you'd like to add the target of monitoring.&lt;/p&gt;
&lt;p align="left"&gt;B-4. Ability to configure SNMP on servers and clients to enable them to emit SNMP messages.&lt;/p&gt;
&lt;p align="left"&gt;B-5. Ability/experience to configure server management tools like Allied Telesyn SwimView, HP OpenView or Dell Server Administrator /IT assistant for PowerEdge Systems.&lt;/p&gt;
(It is okay to use other administrative tools according to the needs at your managed networks. Tools above are just as examples.)&lt;br /&gt;&lt;/blockquote&gt;
Outputs are just like &lt;a href="http://www.geocities.jp/lg_de_sucre/cisco/softether/"&gt;this&lt;/a&gt;.(Special thanks to lg_de_sucre, a cool guy working together.)&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;Howto: Manage logs (delete unwanted/needless log messages)?&lt;br /&gt;
&lt;br /&gt;-&amp;gt; Create jobs (using T-SQL) from SQL Server Enterprise Manager.&lt;br /&gt;
&lt;br /&gt;Howto: merge the route and simplify the system?&lt;br /&gt;
&lt;br /&gt;-&amp;gt; Use SoftEther or other VPN products.&lt;br /&gt;
&lt;br /&gt;Howto: merge outputs of Snort?&lt;br /&gt;
&lt;br /&gt;-&amp;gt; Consult with docs around Snort.&lt;br /&gt;
&lt;br /&gt;&lt;a href="http://www.winsnort.com/"&gt;http://www.winsnort.com/&lt;/a&gt; or &lt;a href="http://www.snort.org/"&gt;http://www.snort.org/&lt;/a&gt; are both good-starts.&lt;br /&gt;
&lt;br /&gt;Ah, it seems I am gonna miss the last train, so see ya later!&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
YamaKen at the office in Tokyo.&lt;br /&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=2193" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Network+Technologies/default.aspx">Network Technologies</category><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Tools/default.aspx">Tools</category><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Interoperability/default.aspx">Interoperability</category><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Windows+management/default.aspx">Windows management</category><category domain="http://msmvps.com/blogs/yamaken/archive/tags/Server+management/default.aspx">Server management</category></item></channel></rss>