Tuesday, April 01, 2008

Top 11 Reasons to Hate Logs

You thought I am done with my Top 11 lists? Nah... here is one more, which actually is designed to bite you in the ass on a certain date. So, "Top 11 Reasons to HATE Logs ... With a Passion."

  1. Read any logs lately? Got bored in 5 minutes - or survived for the whopping 10? Congrats, you score a point! But logs are still boooooooooooooooooooooooooooooring.
  2. One log, two logs, 10 logs.... 1,000,000,000 logs: rabbits and hamsters cannot match the speed with which logs multiply. Don't you just hate that?
  3. You keep hearing people refer to "log data." Then  you run 'tail /var/log/messages' and see text in pidgin English. Where is my data? Hate it!
  4. "Real hackers don't get logged": thus logs are seen as useless - and hated by some "hard core" security pros!
  5. If people lie to you, you hate it. Logs do lie too (see 'false positives') - and they are hated too.
  6. 'Transport error 202 message repeated 3456 times.' Niiiiice. Now go fix that! Fix what? Ah, hate the log obscurity!
  7. Why are there 47 different ways to log that "connection from A to B was established OK?" Or 21 way to say "user logged in OK?" No, really? Why? Who can I kill to stop this insanity?
  8. You MUST do XYZ with logs for compliance. Or you are going to jail, buddy! No, sorry, we can't tell you what XYZ is. Maybe in 7 years; for now, just store everything.
  9. 'Critical error: process completed successfully'  and 'Operation successfully failed' engender deep and lasting hatred of logs in most people. They just do ...
  10. The book called "Ugliest Logs Ever!" is a fat tome, covering every log source from a Linux system all the way to databases and CRM. Bad logs are popular! Bad logs are all the rage among the programmers! Bad logs are here to stay. Bad logs that mean nothing power the log hatred.
  11. "Logs: can't live with them, can't live without them" :-) Hate them we might for different reasons, but we still must collect, protectreview, and analyze them ...

Happy September 1st! :-)

Dr Anton Chuvakin