Re: prelude-correlator

Yoann Vandoorselaere <[email protected]>
Newsgroups gmane.comp.security.ids.prelude.devel
Message-ID <1164964721.4492.81.camel@arwen>
On Wed, 2006-11-22 at 12:52 +0100, Bjoern Weiland wrote:
> >>Every event has a prewikka entry though, which is not very clearly arranged.
> >>I'd love to have these entries correlated, i.e. one prewikka entry for
> >>every *source* IP (regardless of its destination)
> > 
> > This can be done from Prewikka by disabling target host aggregation
> > (click on the "Target" top table header, remove the "Group entry by
> > target" entry).
> 
> Nice one, didn't know about that yet!
> 
> >>Question is, if that is possible with a ruleset for prelude-correlator.
> >>Is the correlator designed for exactly this purpose or (if not) what
> >>else can I use it for then...
> > 
> > You can use Prelude-Correlator to catch the original Nepenthes events,
> > and to construct a Correlation alert carrying all the target carried by
> > the different alerts.
> 
> Is there or will there be some more documentation on how to catch events 
> and construct correlations in the near future?

Hopefully yes! 
Looking at the existing rules collection might already provide you with
some information on how to write new rules.

-- 
Yoann Vandoorselaere | Responsable R&D / CTO | PreludeIDS Technologies
Tel: +33 (0)8 70 70 21 58                  Fax: +33(0)4 78 42 21 58
http://www.prelude-ids.com

_______________________________________________
Prelude-devel site list
[email protected]
http://www.prelude-ids.org/mailman/listinfo/prelude-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.