Solutions for the Maintenance of Event Logs
eventlogs.com

Research
The Event Log Defined
The Syslog Defined
The Event Log and
Today's Enterprise

Event IDs

Strategies
Event Log Management
and the Secure Network

Monitoring Event Logs
Auditing Event Logs
Event Correlation

Solutions
Monitoring Log Files
Collecting Log Files
Auditing Log Files
A Concept for
Total Log Management

Tools
Auditing Volume Analyzer

Monitoring Log Files

Most monitoring tools provide notification options such as e-mail, pager, and some sort of network broadcasted alert. One thing you will want to keep in mind is that most mobile phones and pagers now accept e-mail anyway, so e-mail may be your best option regardless of what feature set you choose. Problems with modem configurations often make e-mail a more reliable choice as well.

You may also want the option of choosing more than just event log monitoring. If your network is like most other enterprises around now, it is a combination of the IT offerings of today and, often, yesterday. Syslog support is often helpful to have not only for the UNIX or LINUX machines that you have around, but you might want the option of keeping an eye on those syslog devices such as routers as well. Novell support in the industry is diminishing, therefore you may have to search a bit more for a good solution to meet any Novell needs.

In the end, the biggest consideration will probably be how easily the software integrates with your enterprise and how easily it is maintained over time. Most software products require the use of agents to perform real time monitoring and notification of the event log.
This is one big thing to look for as it does not always have to be a requirement - the determining factor is most likely your network configuration. If you can opt for a no-agents-required implementation of a monitoring solution, do it. This will save a lot of headaches in the initial implementation, as your network grows, and in the ongoing maintenance of your monitoring solution.


Other resources:

Event Alarm
Event Alarm is a real time monitor of event logs and syslogs.