Re: rules format

"Paul Robert Marino" <[email protected]>
Newsgroups gmane.comp.security.ids.prelude.devel
Message-ID <[email protected]>
well if you are looking to capture information like the log output of an
application then the prelude-lml does support UDP syslog the process itself
is a syslog listener if you configure it to do so.

On 7/10/07, Matt Kettler <[email protected]> wrote:
>
> Jules wrote:
> > Hi there
> >
> >
> >
> > I am trying to learn about prelude.
> >
> >
> >
> >>From I can see, prelude use log files. I am wondering if prelude deals
> with
> > live packet.
> >
> >
> >
> > Any indication of the format used by prelude to capture live data?
> >
>
> In the generally recommended use, Prelude doesn't capture live network
> packets.
>
> Prelude is really a "meta-ids" of sorts. It's essentially a centralized
> logger
> with event correlation, categorization and analysis. Prelude gathers
> information
> from system logs, firewall logs,  NIDS packages (snort), etc and helps you
> identify the important events from the background noise.
>
> For live capture and analysis, you should use snort. prelude-nids does
> exist and
> performs this function, but last I checked it was deprecated in favor of
> snort.
> _______________________________________________
> Prelude-devel site list
> [email protected]
> http://www.prelude-ids.org/mailman/listinfo/prelude-devel
>
_______________________________________________
Prelude-devel site list
[email protected]
http://www.prelude-ids.org/mailman/listinfo/prelude-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.