Lance Spitzner of the Honeynet Project (www.honeynet.org) suggests a trick that's useful for honey (decoy) nets and maybe even for production DMZs: stealth logging. This trick allows a host connected ...
# Sample syslog.conf file that sorts messages by # mail, kernel, and "other", and broadcasts # emergencies to all logged-in users # print most sys. events to tty10 and to the xconsole # pipe, and ...