prelude-correlator
Bjoern Weiland <[email protected]>
| Newsgroups | gmane.comp.security.ids.prelude.devel |
|---|---|
| Message-ID | <[email protected]> |
Hey guys, as I have been told, the SEC correlation is deprecated, prelude-correlator is the new state of the art. As I have none of it used yet, I do have some questions about it. I currently have nepenthes report into prelude and make it viewable via prewikka. Problem is, that nepenthes listens to about 200 IP addresses, so there is a new event raised every few minutes or so which spams my prewikka. Most of the time, there are worms that come from one IP and hit several nepenthes IPs, i.e. one source and several destinations. Every event has a prewikka entry though, which is not very clearly arranged. I'd love to have these entries correlated, i.e. one prewikka entry for every *source* IP (regardless of its destination) Question is, if that is possible with a ruleset for prelude-correlator. Is the correlator designed for exactly this purpose or (if not) what else can I use it for then... -regards, bjoern _______________________________________________ Prelude-devel site list [email protected] http://www.prelude-ids.org/mailman/listinfo/prelude-devel