<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-6193377.post2255386831962954629..comments</id><updated>2012-01-09T17:07:41.330+01:00</updated><category term='gplv3'/><category term='logging'/><category term='astronomy'/><category term='postgres'/><category term='logs'/><category term='log analysis'/><category term='relp'/><category term='funding'/><category term='journald'/><category term='iss'/><category term='open source'/><category term='c programming'/><category term='theclouds'/><category term='suse'/><category term='log normalization'/><category term='troubleshooting'/><category term='reliable'/><category term='rgerhards'/><category term='module'/><category term='imuxsock'/><category term='ihe'/><category term='spam'/><category term='journal'/><category term='reliability'/><category term='adiscon'/><category term='sts-120'/><category term='rsyslog.con'/><category term='unicode'/><category term='performance'/><category term='solaris'/><category term='syslogappliance'/><category term='kids'/><category term='reporting'/><category term='rfc3195'/><category term='appliance'/><category term='phplogcon'/><category term='rate limiting'/><category term='security'/><category term='ommysql'/><category term='building collapse'/><category term='international'/><category term='philosophy'/><category term='log appliance'/><category term='hdfs'/><category term='monitorware'/><category term='forensics'/><category term='rsylsog'/><category term='rsyslog.conf'/><category term='segfault'/><category term='xmas'/><category term='disaster'/><category term='patent'/><category term='config format'/><category term='eventreporter'/><category term='rsyslog'/><category term='software'/><category term='windows event log'/><category term='drm'/><category term='design'/><category term='plugins'/><category term='enterprise logging'/><category term='sbn'/><category term='computing'/><category term='json'/><category term='google'/><category term='space'/><category term='event normalization'/><category term='syslog appliance'/><category term='nasa'/><category term='shuttle'/><category term='hash chaining'/><category term='moon'/><category term='ietf'/><category term='systemd'/><category term='fedora'/><category term='rainer'/><category term='linux journal'/><category term='Adiscon LogAnalyzer'/><category term='carnival of logging'/><category term='logstore'/><category term='libestr'/><category term='lumberjack'/><category term='auditing'/><category term='logtools'/><category term='licensing'/><category term='libeventnorm'/><category term='windows'/><category term='rainerscript'/><category term='cologne'/><category term='apollo'/><category term='libcee'/><category term='human nature'/><category term='log hashing'/><category term='liblogging'/><category term='apache'/><category term='linux'/><category term='liblognorm'/><category term='WinSyslog'/><category term='parallel programming'/><category term='english'/><category term='libee'/><category term='cee'/><category term='syslog'/><category term='sylog'/><category term='config'/><category term='libree'/><category term='time'/><category term='log4j'/><category term='tcp'/><category term='unawe'/><title type='text'>Comments on Rainer's Blog: Feedback Request for digitally signed log store</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.gerhards.net/feeds/2255386831962954629/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6193377/2255386831962954629/comments/default'/><link rel='alternate' type='text/html' href='http://blog.gerhards.net/2011/12/feedback-request-for-digitally-signed.html'/><author><name>Rainer Gerhards</name><uri>https://profiles.google.com/112402185904751517878</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh3.googleusercontent.com/-hYpLVjtOpDc/AAAAAAAAAAI/AAAAAAAAAL4/t7LL3_22bIo/s512-c/photo.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>3</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6193377.post-3643057241713848937</id><published>2011-12-20T13:07:22.204+01:00</published><updated>2011-12-20T13:07:22.204+01:00</updated><title type='text'>Digitally signing the logs provides some evidence ...</title><content type='html'>Digitally signing the logs provides some evidence of log integrity. Many logging and SIEM vendors already include this functionality as a requirement for compliance regulations. Some logging and SIEM vendors offer encryption as well as digital signing of logs because it contains sensitive information on the transactions of services.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6193377/2255386831962954629/comments/default/3643057241713848937'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6193377/2255386831962954629/comments/default/3643057241713848937'/><link rel='alternate' type='text/html' href='http://blog.gerhards.net/2011/12/feedback-request-for-digitally-signed.html?showComment=1324382842204#c3643057241713848937' title=''/><author><name>Observer Journal</name><uri>http://www.blogger.com/profile/08566776052583059609</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://3.bp.blogspot.com/_ZzaH03eRcP0/S3bES1onkpI/AAAAAAAAAbU/FpM_-8lt0P0/S220/Hamburg.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.gerhards.net/2011/12/feedback-request-for-digitally-signed.html' ref='tag:blogger.com,1999:blog-6193377.post-2255386831962954629' source='http://www.blogger.com/feeds/6193377/posts/default/2255386831962954629' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-732683623'/></entry><entry><id>tag:blogger.com,1999:blog-6193377.post-1972699582146693727</id><published>2011-12-19T17:27:30.335+01:00</published><updated>2011-12-19T17:27:30.335+01:00</updated><title type='text'>Thanks John,

I have begun to track the feedback o...</title><content type='html'>Thanks John,&lt;br /&gt;&lt;br /&gt;I have begun to track the feedback on the original article. I think it makes sense to not rush this before the holiday season and then look into the specific cases in January. You are right, a risk profile should be specified.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6193377/2255386831962954629/comments/default/1972699582146693727'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6193377/2255386831962954629/comments/default/1972699582146693727'/><link rel='alternate' type='text/html' href='http://blog.gerhards.net/2011/12/feedback-request-for-digitally-signed.html?showComment=1324312050335#c1972699582146693727' title=''/><author><name>Rainer Gerhards</name><uri>http://www.blogger.com/profile/12765720626924376847</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh3.googleusercontent.com/-hYpLVjtOpDc/AAAAAAAAAAI/AAAAAAAAAAA/scbKoyN8xuo/s512-c/photo.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.gerhards.net/2011/12/feedback-request-for-digitally-signed.html' ref='tag:blogger.com,1999:blog-6193377.post-2255386831962954629' source='http://www.blogger.com/feeds/6193377/posts/default/2255386831962954629' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1449080290'/></entry><entry><id>tag:blogger.com,1999:blog-6193377.post-7353185774526164651</id><published>2011-12-18T02:12:40.636+01:00</published><updated>2011-12-18T02:12:40.636+01:00</updated><title type='text'>A critical thing to do before you get started is t...</title><content type='html'>A critical thing to do before you get started is to understand what risk you would be trying to mitigate. What risk are you solving by digitally signing the log store. &lt;br /&gt;&lt;br /&gt;It would seem to me that the original system creating each event is the one that will need to have signed their individual entry.&lt;br /&gt;&lt;br /&gt;The other big problem with digital signatures is that it is very critical to have a trusted date/time stamp.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6193377/2255386831962954629/comments/default/7353185774526164651'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6193377/2255386831962954629/comments/default/7353185774526164651'/><link rel='alternate' type='text/html' href='http://blog.gerhards.net/2011/12/feedback-request-for-digitally-signed.html?showComment=1324170760636#c7353185774526164651' title=''/><author><name>John Moehrke</name><uri>http://www.blogger.com/profile/04526719420117446030</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.gerhards.net/2011/12/feedback-request-for-digitally-signed.html' ref='tag:blogger.com,1999:blog-6193377.post-2255386831962954629' source='http://www.blogger.com/feeds/6193377/posts/default/2255386831962954629' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-59796725'/></entry></feed>
