Re: rules format
"Paul Robert Marino" <[email protected]>
| Newsgroups | gmane.comp.security.ids.prelude.devel |
|---|---|
| Message-ID | <[email protected]> |
well if you are looking to capture information like the log output of an application then the prelude-lml does support UDP syslog the process itself is a syslog listener if you configure it to do so. On 7/10/07, Matt Kettler <[email protected]> wrote: > > Jules wrote: > > Hi there > > > > > > > > I am trying to learn about prelude. > > > > > > > >>From I can see, prelude use log files. I am wondering if prelude deals > with > > live packet. > > > > > > > > Any indication of the format used by prelude to capture live data? > > > > In the generally recommended use, Prelude doesn't capture live network > packets. > > Prelude is really a "meta-ids" of sorts. It's essentially a centralized > logger > with event correlation, categorization and analysis. Prelude gathers > information > from system logs, firewall logs, NIDS packages (snort), etc and helps you > identify the important events from the background noise. > > For live capture and analysis, you should use snort. prelude-nids does > exist and > performs this function, but last I checked it was deprecated in favor of > snort. > _______________________________________________ > Prelude-devel site list > [email protected] > http://www.prelude-ids.org/mailman/listinfo/prelude-devel > _______________________________________________ Prelude-devel site list [email protected] http://www.prelude-ids.org/mailman/listinfo/prelude-devel