Werner Rumpeltesz recently updated his free HTTP Logstat tool (v. 1.2.1). I downloaded it and took it for a test drive. The tool works fine with Windows XP but in my case it crashed under Vista.
With the help of Webmin I downloaded some Apache logfiles of one of my servers.
---
Possible interesting logfiles (Linux server):
/var/log folder:
auth.log (but also auth.log.0, auth.log.1.gz etc.as logfiles are rotating)
daemon.log
mysql.log
syslog
user.log
/var/log/apache2 folder:
access.log (access.log.1, access.log.1.gz etc.)
error.log (error.log.1, error.log.1.gz etc.)
Several other logfiles can exist on a server, as some programs tend to create and maintain their own specific logs.
---
In this testcase, I use HTTP LogStat to study the contents of access.log.2.gz, which I have copied to my local pc:
First thing I do now is change the language of the tool, as German is not my favorite language. Click in Extras to do so.
Now, you have to make a profile for you server.

This seems to be an unnecessary step to take, but the tool doesn't work without a profile.
Now, I can select the logfile I have downloaded from my server (Path / file mask)
After this you can create a report

The tool creates a very clear report. You can find an example here.
The free HTTP LogStat tool is a great help to learn more about your own server or to use in hack investigations.
Recent Comments