David Coulson on 31 Jan 2011

Re: [PLUG] iptables question

On 1/31/2011 2:16 PM, Robert Spangler wrote:
While logging is good thing, to much logging is a nightmare.  For the simple
reason you fill up your logs with information that is useless and going over
the logs is a task because you have too much useless information in them.
What do you care if someone is trying to log into port(s) you don't have
I'm confused what you mean by 'open ports' - Do you mean something that has a service listening on it, or a port open in iptables?

I pretty much don't log anything. Way too much garbage and 99% of the time there is a problem it's reproducible when I can watch it with tcpdump.
