Session recording
Paul Lussier
p.lussier at comcast.net
Mon Mar 31 12:52:52 EDT 2008
Bill McGonigle <bill at bfccomputing.com> writes:
> I see you've already found lastcomm and friends, but it would be great
> to know what you come up with for a correlation mechanism.
Can't you log everything possible via syslog, then write wrappers
around lastcomm, sa, sar, et al to dump that data to file, and point
splunk at the whole mess and let it do the time-event correlation for
you?
--
Seeya,
Paul
More information about the gnhlug-discuss
mailing list