In the past I have waxed enthusiastically about Mandiant's Highlighter log parsing tool. It is simply an amazing time saver for anyone who needs to parse fixed format log files such as firewall logs. The biggest limitation of the early versions of Highlighter was that it could not handle large files. Not anymore...as of version 1.1.1 which was recently released, Highlighter now has large file support and a number of other new features.
Highlighter can be downloaded for free from the software section of Mandiant's website.
More information on this release can be found at the Mandiant Blog.
-- Rick Wanner - rwanner at isc dot sans dot org
May 19th 2009
9 years ago