Good sarc monitoring tip



Sarc is still in their month of security tips per day and todays is another good one. Todays tip is about monitoring machines, particularly those that “defend” your network. (Mail antivirus scanners/ proxy fitlers/scanners/etc.) The core of the advice is to not just ping – that only tells you if the system exists and is online – it doesn’t tell if things are working. They suggest scripting tests (antivirus scanner can be tested via the EICAR test signature for instance.) They note that doesn’t tell if the av scanner is updated (I prefer a crontab output of the days updates – looks like there were around 9 clamav signature updates yesterday.


I know, some of you are thinking, but I don’t want that much mail everyday. If you’re using a linux based system for monitoring you can script things in a number of ways. You can have the monitoring continually running and not contact you unless there’s a problem. (I have a tendency to use temporary files to hold the status of a service and then compare current results of a check to the last (in the temporary file) if the status has changed it will let me know, if all is the same I won’t be pestered by continual messages.) The only problem with this approach is if you start tuning out the messages because they’re too frequent. (That’s why it’s useful to improve your scripts to only notify you of changes.)

Related Posts

Blog Traffic Exchange Related Posts
  • Linspire's Click n run is now free First, Linspire released the freely available "freespire" release of their operating system (based on debian linux). Now, users will no longer have to pay an annual subscription for the click n run service. That's now available for free as well. There is a writeup here. Previously the annual subscription fees......
  • Clamantivirus may get support from eEye? This would be a good thing for clamantivirus. eEye is considering "adopting" clamav for inclusion in their Blink product. The idea is that they would improve clamantivirus and then start integrating it as antivirus scanning functionality in their product. This would be really promising for the prospects of having clamav......
  • Major botnet building and the massive jump in spam For a few months now (since the demise of bluefrog actually) I've noticed that the level of junk mail has gone up on my own mail server. Yes, I use spamassassin to filter and tag, but the volume of stuff that's tagged has gone up (as well as the volume......
Blog Traffic Exchange Related Websites
  • Protecting Your Computer with Free Antivirus Software - A Good Deal ? If you're like many college students today, you depend on your computer for your education. Papers are planned, researched , and written with it. Group project assignments are broken down and delegated online. Without a computer, you'd probably have a hard time getting things done efficiently. Your computer is a valuable tool for......
  • How to Create Alternative Income If you're currently living paycheck to paycheck, or you would just like to have a little more financial security, the key is creating alternative forms of income. While to many people this means getting a second job, there are actually easier ways that you can start bringing in more money......
  • ScanShell Store - Business Card Scanner document.write(''); Stop typing customer info into your computer. Start scanning their business cards and documents for a speedy data entry and database creation. We sell all manner of scanning solutions including Business Card scanner, ID scanner, Medical card scanner, Driver License scanner, portable scanner and much more. We offer......
PDF24    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site