Download Sawmill 8.8.1
30 Days Free Trial
Home Products Downloads Purchase Support About About
Sawmill Sawmill



Sawmill has plug-ins to support the following log formats:


Sawmill is a Sourcefire Snort 2 (syslog required) log analyzer (it also supports the 1021 other log formats listed to the left). It can process log files in Sourcefire Snort 2 (syslog required) format, and generate dynamic statistics from them, analyzing and reporting events. Sawmill can parse Sourcefire Snort 2 (syslog required) logs, import them into a MySQL, Microsoft SQL Server, or Oracle database (or its own built-in database), aggregate them, and generate dynamically filtered reports, all through a web interface. Sawmill can perform Sourcefire Snort 2 (syslog required) log analysis on any platform, including Windows, Linux, FreeBSD, OpenBSD, Mac OS, Solaris, other UNIX, and others.

Sawmill stores the following non-numerical fields in its database for Sourcefire Snort 2 (syslog required), generates reports for each field, and allows dynamic filtering on any combination of these fields:

Field  Internal Name
   source IP  source_ip
   destination IP  destination_ip
   source port  source_port
   destination port  destination_port
   classification  classification
   snort priority  snort_priority
   protocol  protocol
   rule number  rule_number
   rule  rule
   message  message
   location  location

Sawmill stores the following numerical fields in its database for Sourcefire Snort 2 (syslog required), aggregating them and including them as columns in most reports:

Numerical Field  Internal Name
   events  events

See Sawmill Features to learn more about Sawmill's options for viewing, customizing, filtering, exporting and scheduling Sourcefire Snort 2 (syslog required) reports.

Sawmill also supports 1021 other log formats.

© 2024 Flowerfire | Copyright | Privacy Policy | License Agreement | Terms of Use | Contact | Feedback | About
Sawmill Software
Sawmill Software
Back to Sawmill Home