What consequences to take from what i read in logfiles?

Posted by Helene Bilbo on Server Fault See other posts from Server Fault or by Helene Bilbo
Published on 2012-09-23T16:01:42Z Indexed on 2012/09/24 3:40 UTC
Read the original article Hit count: 517

Since some weeks i manage my first Webserver, a Seaside application behind an Apache proxy on Linode, and i installed logwatch to send me daily logs.

Where can i get information on when i have to act as a consequence of what i read in these logwatch reports?

For example i read that all kinds of people try to login on funny nonexisting accounts or all kinds of webcrawlers test for nonexisting cms login pages, some ip adresses get banned and unbanned by fail2ban...

I assume that's normal? Is it? But how do i know that i probably have to do something? What do i look for in the logs?

© Server Fault or respective owner

Related posts about security

Related posts about webserver