Author : adisconteam

Adiscon products and the Microsoft SQL Server 2000 Desktop Engine

Adiscon products and the Microsoft SQL Server 2000 Desktop Engine Created 2003-07-24 by Lutz Koch. How do MSDE security risks relate to Adiscon products? As a general policy, MSDE is *not* installed with any of our products. Even though this may cause some additional setup work for customers, we have decided to do so because […]

How to setup file monitoring for ISA Server?

How to setup file monitoring for ISA Server? Created 2003-05-23 by Lutz Koch. How to setup file monitoring for ISA Server? Since ISA Server logfiles are W3C based simple textfiles, they can be processed by MonitorWare Agent. To monitor the ISA logfiles, you just have to setup a File monitor service in the Agent: Right-click […]

How to create complex filter conditions?

How to create complex filter conditions? Created 2003-05-13 by Usman Khawaja. I would like to create some more complex filters by combining ANDs and ORs. (condition “a” AND condition “b”) OR (condition “c” AND condition “d”) OR … where “condition a” could be one of the choices like “syslog priority < 4 “, etc. In […]

Configuring Windows for the Event Log Monitor

Article created 2003-05-12 by Rainer Gerhards. Configuring Windows for the Event Log Monitor The event log monitor service pulls events from the Windows event logs. In Windows’ default setup, the information contained in the logs is sparse and far from sufficient for security monitoring. If you are solely interested in checking system health, the default […]

Creating a hardened log host

Step-By-Step Guides Article created 2003-05-12 by Rainer Gerhards. Creating a hardened log host A hardened log host is a system that is especially configured to prevent malicious users from modifying any log data stored inside it. A hardened log host is especially useful if tampering with log data is to be avoided. Setting up a […]

Difference between ReceivedAt and DeviceReportedTime

Difference between ReceivedAt and DeviceReportedTime Created 2003-05-10 by Wajih-ur-Rehman. What is the difference between ReceivedAt and DevicedReportedTime? I will explain you the difference by giving you two different scenarios: Scenario 1: Using MonitorWare Agent as Event Log Monitor and Forwarding the data to another MonitorWare Agent using Syslog In this case, the DeviceReportedTime is actually […]

Reporting Log Truncation

Step-By-Step Guides Article created 2003-05-09 by Tamsila-Q-Siddique. Reporting Log Truncation This step-by-step guide was inspired by a customer question. The customer had a need to record all events seen in the event logs. But due to the overall setup, a lot of event log truncated messages occured. These, too, should be forwarded, but only one […]

Firewall setup for MonitorWare Agent

Step-By-Step Guides Article created 2003-05-09 by Rainer Gerhards. Firewall setup for MonitorWare Agent MonitorWare Agent can be used with standard firewalling. The product itself does not require any specific access privileges to network services like RPC or the like. The Windows networking support required is fully dependant on the needs of the network or security […]

Intrusion Detection via the Windows Event Log

Step-By-Step Guides Article created 2003-05-09 by Rainer Gerhards. Intrusion Detection via the Windows Event Log The Windows event log provides multiple evidence of potential intrusions. We will discuss what to look for when checking the event log. We have used Windows 2000 Server while creating this text. There may be differences for other versions, so […]

Scroll to top