Log file management tramite syslog-ng Piergiorgio Venuti

Log File Management with the Cyberfero service

IT systems produce large quantities of log files, very useful tools for guaranteeing data security and application stability. However, in a complex ecosystem, the quantity of files and their location can become two insurmountable obstacles to overcome, in case it is necessary to consult the data efficiently. This is where log management systems come into play, which thanks to technologies such as Syslog-ng, are able to circumvent the problem. In the article, we see how a log file management solution can be a valuable investment.

What is a log file, what is it for

Any action that is performed on a machine or by it can be recorded in a log file. To understand what it is, let’s imagine that it is a ship’s logbook, in which every single event that happened on the boat is noted. In fact, the name derives from the nautical environment, in which the use of a logbook was common. This was nothing more than a diary in which navigation data were recorded at regular intervals: speed, wind strength and direction, water conditions and so on.

With the concept of recording useful information in a file that can be consulted later, the log file contains any changes, actions, states or modifications for security reasons. In case something goes wrong, it is easy to understand what happened by consulting a log file. This is especially true when we talk about servers and applications, data dissemination, IT security, etc.

Amount of log files

Some companies have up to a few dozen servers, others have hundreds, some thousands, and there are others that manage tens of thousands of servers. These systems produce a huge amount of data in the form of log files.

Complicating things is IT architecture. Very often machines are organized into subsystems, both for reasons of convenience and safety. In the unfortunate event that someone wants to consult the log files following an accident, we should despair. Which server holds the data we are interested in? Which subsystem is it in? These are not questions that can be answered simply, especially if you don’t know the source of the problem.

The management of the log files of a system (or Log Management) is essential in the collection of data, prevention and resolution of problems.

Cyberfero Log Management

SOD offers a log management solution through Syslog-ng Premium Edition agents. These are in charge of the collection, transmission and storage of log files. Not only are they collected and centralized in a single virtual place, but the data are also normalized, ie “translated” into standardized formats so that they can be consulted and compared more easily.

Real-time normalization, reporting and classification

Thanks to normalization, it is possible to carry out cross-sectional full-text searches in a few seconds to all the log files collected. Complex operations are guaranteed by the possibility of using wildcards and Boolean operators. The analysis of the collected data is therefore very simplified, which allows the data to also be used to monitor the efficiency of the system, identify possible future problems and intervene before it is too late.

It is also possible to generate customized reports consisting of graphs and statistics with the aim of certifying compliance with standards and regulations such as PCI-DSS, ISO 27001, SOX and HIPAA.

One of the most interesting features of syslog-ng is the ability to automatically classify messages and sort them into classes. These can then be used to label the type of event described in the log. Examples of possible classes: user login, application crash, file transfer, etc.

Extraction and correlation of messages in log files

The classification of messages opens the door to a further functionality: the extraction and correlation of messages. Once each message contained in the log file has been normalized and classified according to your needs, it is possible to assign different tags, to add an additional filter level.

To give an example: once a user’s login messages have been collected, it is possible to label them as user_login, and then isolate them by extracting them and collecting them in a separate file to perform further processing on these messages.

Syslog-ng also makes it possible to correlate events in real time, to prevent data from a single event being scattered across multiple log files. For example, the access and exit data (log-in and log-out) are often recorded far from each other, even in different log files. Through correlation, the data of a single event can be collected and analyzed in isolation.

Automatic backup

The stored log messages and the configuration of the Log Management service can be periodically transferred to a remote server using the following protocols:

– Network File System protocol (NFS)
– Rsync over SSH
– Server Message Block protocol (SMB / CIFS)

Performance

The log file collection and management system with syslog-ng PE agents operates on over 50 platforms, including all Linux distributions and commercial versions of Unix and Windows. The service is able to manage huge quantities of messages, up to over 100,000 per second and over 70 GB of raw log files per hour, from 5000 different sources (servers, applications, etc.).

Ask us for more information about our Log Monitoring service to know specifically how it can be implemented in your systems and how it can help you.

[btnsx id=”2931″]

Useful links:

Log Management

Log Management features

New service | Log Management – High performance service for collecting logs

 

 

 

Share


RSS

More Articles…

Categories …

Tags

RSS feed: Unknown Feed Unknown Feed

RSS feed: Full Disclosure Full Disclosure

  • [0day-rubbish] VMS 6.48.809 Authenticated command injection to root RCE (8.8) August 20, 2026
    Posted by disclosure via Fulldisclosure on Aug 190day Rubbish Research Team is publicly disclosing a vulnerability in VMS 6.48.809. Type: Authenticated command injection to root RCE (CWE-78) CVSS: 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) Impact: Authenticated attacker executes arbitrary commands as root via unsanitized command injection Authentication: authenticated Full technical analysis and a reproducible proof-of-concept:...
  • [0day-rubbish] ONE Reporter 13.1 Authenticated RCE / privilege escalation via CommandExecutor (8.8) August 20, 2026
    Posted by disclosure via Fulldisclosure on Aug 190day Rubbish Research Team is publicly disclosing a vulnerability in ONE Reporter 13.1. Type: Authenticated RCE / privilege escalation via CommandExecutor (CWE-78) CVSS: 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) Impact: Low-privilege user executes arbitrary commands as local-admin service account Authentication: authenticated Full technical analysis and a reproducible proof-of-concept:...
  • [0day-rubbish] Gemini 7.3.0 Authenticated SQL injection to xp_cmdshell RCE (8.8) August 20, 2026
    Posted by disclosure via Fulldisclosure on Aug 190day Rubbish Research Team is publicly disclosing a vulnerability in Gemini 7.3.0. Type: Authenticated SQL injection to xp_cmdshell RCE (CWE-89) CVSS: 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) Impact: Authenticated user executes OS commands via stacked SQL and xp_cmdshell as sa/sysadmin Authentication: authenticated Full technical analysis and a reproducible proof-of-concept:...
  • [0day-rubbish] RoboTask 11.0.5.1229 Unauthenticated REST API remote task execution (9.8) August 20, 2026
    Posted by disclosure via Fulldisclosure on Aug 190day Rubbish Research Team is publicly disclosing a vulnerability in RoboTask 11.0.5.1229. Type: Unauthenticated REST API remote task execution (CWE-306) CVSS: 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) Impact: Unauthenticated attacker enumerates and triggers pre-existing tasks with Administrator privileges Authentication: unauthenticated / pre-auth Full technical analysis and a reproducible proof-of-concept:...
  • [0day-rubbish] ActiveFax Server 10.70 Unauthenticated LPD Ghostscript %pipe% SYSTEM RCE (9.8) August 20, 2026
    Posted by disclosure via Fulldisclosure on Aug 190day Rubbish Research Team is publicly disclosing a vulnerability in ActiveFax Server 10.70. Type: Unauthenticated LPD Ghostscript %pipe% SYSTEM RCE (CWE-78) CVSS: 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) Impact: Unauthenticated attacker executes arbitrary commands as SYSTEM via an LPD print job Authentication: unauthenticated / pre-auth Full technical analysis and a reproducible proof-of-concept:...
  • [0day-rubbish] Tornado 2.11.3 Unauthenticated arbitrary file write to root RCE (storeTo=file: to cron) (9.8) August 20, 2026
    Posted by disclosure via Fulldisclosure on Aug 190day Rubbish Research Team is publicly disclosing a vulnerability in Tornado 2.11.3. Type: Unauthenticated arbitrary file write to root RCE (storeTo=file: to cron) (CWE-22) CVSS: 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) Impact: Unauthenticated attacker writes arbitrary files and achieves root command execution via cron Authentication: unauthenticated / pre-auth Full technical analysis and […]
  • [0day-rubbish] Datalore On-Premises 2026.2.3 Unauthenticated RCE via InteractiveReport access-mapping flaw (9.8) August 20, 2026
    Posted by disclosure via Fulldisclosure on Aug 190day Rubbish Research Team is publicly disclosing a vulnerability in Datalore On-Premises 2026.2.3. Type: Unauthenticated RCE via InteractiveReport access-mapping flaw (CWE-306) CVSS: 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) Impact: Anonymous attacker executes arbitrary code in the notebook agent container Authentication: unauthenticated / pre-auth Full technical analysis and a reproducible proof-of-concept:...
  • APPLE-SA-08-18-2026-1 Safari 26.6.1 August 20, 2026
    Posted by Apple Product Security via Fulldisclosure on Aug 19APPLE-SA-08-18-2026-1 Safari 26.6.1 Safari 26.6.1 addresses the following issues. Information about the security content is also available at https://support.apple.com/148286. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. WebKit Available for: macOS Sonoma and macOS Sequoia Impact: Processing maliciously […]
  • Cudy WR3000: Hard-coded JWT Secret to Root Command Injection August 20, 2026
    Posted by Nir Yehoshua on Aug 19Hello Full Disclosure list, Cipher Security Labs has published details for two vulnerabilities affecting Cudy WR3000 hardware revision 2.0 running firmware before version 2.5.24. CVE-2026-71960 - Hard-coded JWT Secret Authentication Bypass Severity: Critical, CVSS 9.3 The device firmware contains a hard-coded HMAC signing secret used by the Mosquitto MQTT […]
  • Security advisory: Pre-authentication RCE (SQL injection) in XPressEntry 3.7.7454 (Telaeris Inc) August 18, 2026
    Posted by disclosure via Fulldisclosure on Aug 170day Rubbish Research Team is publicly disclosing a vulnerability in XPressEntry 3.7.7454 (Telaeris Inc). The research is published and a proof-of-concept is available. Pre-authentication RCE (SQL injection) (CVSS 9.8, pre-authentication) Telaeris XPressEntry 3.7.7454 runs its main HTTP API without authentication when RequireReaderCredentials is False, which is the default. […]

Customers