Finding Events that have "Never Been Seen" Before
by Ron Gula on December 26, 2006
A useful event to know about on any network is when something new happens on a given server for the first time. This is a very simple concept and extremely useful.
Regardless if your event logs are from UNIX systems, router access control violations, wireless access DHCP logs, intrusion detection systems or so on, after a certain period of time, the same events tend to repeat themselves. This is because most of our networks run controlled and automated processes.