On the SSG you can direct both traffic and event log information to a syslog server.
set syslog config x.x.x.x log all ( This sends everything you can parse it down to just specifics if you dont need such verbose logging. If you wish just for the event log or the traffic log just specify that instead of all)
set syslog enable
save
The facility by default is local0
You can change this by using the command
set syslog config x.x.x.x facilities localx
save
Now on your linux box. Configure syslogD or syslog-ng and use logwatch to parse for specific events you wish to alert on.
How to use Syslog-ng
Hope this points you in the right direction.
Message Edited by shadow on 09-07-2008 11:34 AM