Re: prelude-correlator
Yoann Vandoorselaere <[email protected]>
| Newsgroups | gmane.comp.security.ids.prelude.devel |
|---|---|
| Message-ID | <1164964721.4492.81.camel@arwen> |
On Wed, 2006-11-22 at 12:52 +0100, Bjoern Weiland wrote: > >>Every event has a prewikka entry though, which is not very clearly arranged. > >>I'd love to have these entries correlated, i.e. one prewikka entry for > >>every *source* IP (regardless of its destination) > > > > This can be done from Prewikka by disabling target host aggregation > > (click on the "Target" top table header, remove the "Group entry by > > target" entry). > > Nice one, didn't know about that yet! > > >>Question is, if that is possible with a ruleset for prelude-correlator. > >>Is the correlator designed for exactly this purpose or (if not) what > >>else can I use it for then... > > > > You can use Prelude-Correlator to catch the original Nepenthes events, > > and to construct a Correlation alert carrying all the target carried by > > the different alerts. > > Is there or will there be some more documentation on how to catch events > and construct correlations in the near future? Hopefully yes! Looking at the existing rules collection might already provide you with some information on how to write new rules. -- Yoann Vandoorselaere | Responsable R&D / CTO | PreludeIDS Technologies Tel: +33 (0)8 70 70 21 58 Fax: +33(0)4 78 42 21 58 http://www.prelude-ids.com _______________________________________________ Prelude-devel site list [email protected] http://www.prelude-ids.org/mailman/listinfo/prelude-devel