Cover V05, I12
Article
Figure 1
Figure 2
Table 1

dec96.tar


Figure 2: Example syslog file (Solaris 2.5)

Aug 3 19:45:56 escape in.ftpd[26138]: warning: host name/name
mismatch: www.x.x !=x.com
Aug 4 00:01:53 escape sendmail[16964]: AAA16964: from=root, size=81,
class=0, pri=30081, nrcpts=1, msgid=<199608040501.AAA16964@escape.>,
relay=root@localhost
Aug 4 00:01:54 escape sendmail[16965]: AAA16964: to=systems@duffel.net,
ctladdr=root (0/1), delay=00:00:01, mailer=ether,
relay=mail.duffel.net. [XXX.58.152.2], stat =Sent (Ok)
Aug 4 00:04:13 escape sendmail[16990]: AAA16990: from=<info-dylan-digest-
owner@cambridge.apple.com>, size=2039, class=0, pri=32039,
nrcpts=1, msgid=<199608040500.BAA13065@ministry.cambridge.apple.com>,
proto=SMTP, relay=hp1.online.apple.com [192.215.65.17]
Aug 4 00:04:13 escape sendmail[16991]: AAA16990: to=<jbp@net.com>,
delay=00:00:02, mailer=local, stat=Sent
Aug 4 00:07:15 escape in.ftpd[16993]: connect from treasure-d7.XXX.com
Aug 4 00:08:15 escape in.ftpd[16998]: connect from competitors.host.com
Aug 4 00:11:31 escape sendmail[17002]: ws8.emerge.com [XXX.158.249.10]:
EXPN webmaster
Aug 4 00:13:43 escape in.ftpd[17003]: connect from sac-XXX-08.ix.net.com
Aug 4 00:15:30 escape in.ftpd[17005]: connect from sac-XXX-08.ix.net.com
Aug 4 02:02:07 escape in.ftpd[24719]: warning: can't verify hostname:
gethostbyname(unknown.x.x) failed
Aug 4 05:07:00 escape qpopper[17239]: connect from lax-XXX-08.ix.net.com