It performs log analysis, integrity checking, Windows registry monitoring, rootkit detection, real-time alerting and active response
Centralized Syslog Server Using syslog-NG with web Interface using php-syslog-ng
Fail2ban scans log files like /var/log/pwdfail or /var/log/apache/error_log and bans IP that makes too many password failures