The use of a “syslog” server is important in today’s data center.
Most network and SAN switches, along with Unix and Linux servers are
capable of sending logging information to a syslog server. The obvious
reason for a syslog server is to centralize all of your logs. This
enables you to troubleshoot issues more efficiently. Most syslog
servers allow you to do a time-line based analysis of log data so that
you have an enterprise – wide view of all activity. This allows you to
see how different devices interact.
An less obvious reason for a syslog server is for security purposes.
The theory is that an attacker will attempt to elevate to root
privileges and then try to delete or alter logs to hide evidence of the
attack. If all log information is relayed to a syslog server, the hope
is that this data is secured for forensic study, if needed.
Read more…