All,
I have posted (in this case, re-posted) two more log bundles:
1. Firewall logs
2. Correlated syslog + Apache + firewall + NIDS logs.
The second bundle allows for a lot of fun to be had since it has logs
covering the same time frame from multiple systems on the same
network. You can test your correlation system using these logs - and
have it fail in a spectacular fashion :-) due to slight lack of time
sync in the log timestamps.
Also, these two log bundles has a bit of analysis posted online.
Please see links at
log-sharing.dreamhosters.com.
Anton