| Log Standards and Future Trends |
As some of you know, I’ve done this BrightTalk Log Management web conference the other week. My presentation was about “Log Standards and Future Trends.” Here is an embed of my presentation with voice. If you just want this slides, go check the Slideshare version. Enjoy! Possibly related posts:


 |
| Monthly Blog Round-Up – August 2010 |
Blogs are 'stateless' and people often pay attention only to what they see today. Thus a lot of useful security reading material gets lost. These monthly round-ups is my way of reminding people about interesting blog content. If you are “too busy to read the blogs,” at least read these. So, here is my next monthly 'Security Warrior' blog round-up of top 5 popular posts/topics this month.
- My super-rant about log analysis “Pathetic Analytics Epiphany!” has shot to the top like a pig kicked up in the ass by an irate giant. It is about how after looking at logs for so many years, we still use primitive approaches and primitive tools.
- Not surprisingly, my belated reading of the Verizon Breach Reports 2010 (“Verizon Breach Report 2010 OUT!”) is in my Top5. VzDBIR is pure awesomeness, as always!
- “Updated With Community Feedback SANS Top 7 Essential Log Reports DRAFT2”, “SANS Top 5 Essential Log Reports Update!” and their predecessor “Top5 SANS Log Reports Update DRAFT” finally beat the previous champion of a few months “Simple Log Review Checklist Released!” Now I just need to document all the chosen favorite reports and submit it for community release.
- Career posts always get top scores automatically and “Skills for Work vs Skills for Getting Hired” is no exception. Just as its predecessor, “Myth of an Expert Generalist”, it got on my monthly Top 5 posts immediately, was featured on Reddit.com, etc, etc. The next career post is coming soon…don’t despair :-)
- News of sinking SIEM and log management vendors alluded to in “To Those Escaping from Sinking SIEM/Log Management Vendors” somehow made it to the top. Maybe links to SIEM jobs did it?
- “How Do I Get The Best SIEM?”, a companion to “On Choosing SIEM“, went to the top like lighting a few months ago and stayed there this month as well. If you are thinking of getting a SIEM or a log management tool, check them out and also look at related resources at the end of these posts. “The Myth of SIEM as “An Analyst-in-the-box” or How NOT to Pick a SIEM-II?” and ““I Want to Buy Correlation” or How NOT to Pick a SIEM?” also stay at the top – it seems like smaller organizations are looking at deploying SIEM and log management and there is a lot of interest in simple guidance on this.
Also, below I am thanking my top 5 referrers this month (those who are people, not organizations). So, thanks a lot to the following people whose blogs sent the most visitors to my blog:
- Michał Wiczyński
- Raffael Marty
- Dancho Danchev
- Cédric Blancher
- JP Bourget
See you in September; also see my annual “Top Posts” - 2007, 2008, 2009! Possibly related posts / past monthly popular blog round-ups:
 

 |
| LogChat Podcast 1: Anton Chuvakin and Andrew Hay Talk Logs |
'LogChat' Podcast is born! Everybody knows that all this world needs is a podcast devoted to logs, logging and log management (as well as SIEM, incident response and other closely related subjects).
And now you have it - through the sheer combined genius of Andrew Hay and myself, Anton Chuvakin.
Administrative items first:
- We need a new name! We are not entirely happy with 'LogChat' and, sadly, 'LogTalk' is taken. Please suggest a name - if we pick yours, you get a free signed copy of my 'PCI Compliance' book.
- We will post the transcript, not just the MP3 file - in a few days. If you have ideas for a good/inexpensive transcribing service, we are all ears. I will try Amazon Mechanical Turk first, but it might not be good enough for a technical podcast.
- Please also suggest topics to cover as well - even though we are not likely to run out of ideas for a few years. Our first topic today is new log source integration - if it sounds boring...well...listen first/judge second :-)
- We plan for this to be a monthly podcast. So, the next one will happen sometime early October.
- Any other feedback is HUGELY useful. Is it too long? Too loud? Not enough jokes? Too few mentions of the 'cloud'? Feedback please! Who knows...maybe there are more PCI books left in my secret stash and you too will earn that glorious prize for the most useful piece of feedback :-)
And now, in all its, glory - the podcast: the link to MP3 is here [MP3]. UPDATE: RSS feed is here.
Enjoy the log chat!

 |