Learning Logs

Sharing our logging knowledge. A place we log our insights, experiences, and findings as it pertains to the world of logs.

Full text logging search

Everything you don't need to know about NGINX error logs

NGINX is the most popular web server in the planet and in this post, we will analyse their error logging in detail.







Posted in nginx     /   2022-06-12

Web Interface for OSSEC

The OSSEC HIDS platform is a popular log collection and analysis platform, this article shows how you can implement a web interface for the OSSEC platform.







Posted in logging   ossec   ossec-wui     /   2022-06-06

Brute force attacks against Windows Remote Desktop

In this article we breakdown Brute force attacks against Windows Remote Desktop (RDP) that have been happening against our server on Azure.







Posted in windows   brute_force     /   2022-06-05

Syslog Daemons difference (syslogd, rsyslog and syslog-ng)

This article explains the differences between the different syslog daemons: syslogd, rsyslog and syslog-ng, found in Linux and BSD distributions.







Posted in syslog   rsyslog   syslog-ng     /   2022-06-02

A Guide to Dropbear Logs

Understanding the logs from Dropbear, a SSH server meant for low memory systems. Useful to understand the logs from your routers, including OpenWrt, Ubiquiti, Unifi, etc.







Posted in logging   sshd   dropbear     /   2022-06-02

Learn How to Test System Logging with Logger

Logger is a command-line tool for Linux and BSD systems that allow you to easily test and send logs to syslog.







Posted in logging   logger     /   2022-06-02

A Guide to Ubuntu Linux Logging

Ubuntu is a popular linux distribution and this article explains how logs are generated, where they are stored, and what they capture.







Posted in logging   ubuntu     /   2022-06-02

A Guide to NGINX Logs

NGINX is a powerful web server and logging is a critical piece to managing a web server. In this article we explain the two log types: access and error, and how to work with them.







Posted in logging   nginx   weblogs     /   2022-06-02

Trunc - What Events to Log to your central logging server

In this article we explore the best practices and the type of events that you should always store in your central logging server.







Posted in logging   log-management     /   2022-06-02

Log Management Challenges

Log management is difficult because of the shear scope of devices that need to be monitored.







Posted in logging   log-management     /   2022-06-02

A Guide to Apache Logs

Apache is a powerful web server and logging is a critical piece to managing a web server. In this article we explain the two log types: access and error, and how to work with them.







Posted in logging   weblogs   apache     /   2022-06-02

Troubleshooting Remote Syslog with TCPDUMP

How to troubleshoot remote syslog with tcpdump. rsyslog, syslog-ng, linux, ubuntu, red hat, centos







Posted in logging   tcpdump   syslog     /   2022-06-02

But don't just believe us. Try yourself.