Re: Prelude support for Ossec

Robin Gruyters <[email protected]>
Newsgroups gmane.comp.security.ids.prelude.devel
Message-ID <[email protected]>
Sebastien,

Great to see that OSSEC is going to support Prelude Framework. Altough I'd
encounter a problem when trying to install it.

I'd run 'make setprelude' in the src/ tree, and I can see that I have the
following entries in my Config.OS file:

CEXTRA= -DDEFAULTDIR=\"/var/ossec\" -DLOCAL
DEXTRA=-DUSE_OPENSSL
TEXTRA=-pthread
CPRELUDE=-DPRELUDE -I/usr/local/include

When I run './install.sh' from the root installation dir. I noticed that the
Config.OS gets overwritten, just before it starts to compile.

At the moment I have done it manually, but I think/hope this will be fixed 
in the next (beta) release.

Kind regards,
-- 
Robin Gruyters
Network and Security Engineer
YIRDIS - Betronic Services
I: http://yirdis.com
I: http://betronic.nl
P: +31 (0)20 5659191
F: +31 (0)20 5659190

On Sun, Oct 07, 2007 at 10:50:11PM +0200, Sebastien Tricaud wrote:
> Hello people,
> 
> I am happy the announce the prelude support in the upcoming Ossec release.
> 
> 
> What is it?
> ======
> 
> OSSEC is an Open Source Host-based Intrusion Detection System. It
> performs log analysis, integrity checking, Windows registry
> monitoring, rootkit detection, real-time alerting and active response.
> 
> 
> Download it!
> ========
> 
> The prelude code is currently in CVS, but you can get a nightly snapshot here :
> http://www.ossec.net/files/snapshots/ossec-hids-071006.tar.gz
> 
> 
> Compile it!
> ======
> 
> You must go into the src/ directory and type "make setprelude". Then
> you can go back to the sources root and run the "install.sh" script.
> Since this is beta, that's how you should do it, things will be easier
> for the official release (simple question such as "do you want to
> enable prelude support ?").
> 
> 
> Install it!
> =====
> 
> It is installed just like a regular sensor (intructions ->
> https://trac.prelude-ids.org/wiki/RegisteringASensor).
> 
> Two *important* things to keep in mind :
> * When performing registration, the "Ossec" group and user must be
> registered instead of root, since Prelude code runs as part of the
> analysis section of the Ossec program. And Ossec runs this code under
> both ossec user and group.
> * In the configuration file "ossec.conf", you should add the following
> line in the <global> section :
> <prelude_output>yes</prelude_output>
> 
> 
> Issues
> ====
> 
> IDMEF Messages are not as full as I would like them to be, this is
> because I live in Paris, which is a very fun city to be in, and there
> are a lot outdoors activities that I do here. I promise to reduce my
> social activities to have something more exhaustive.
> 
> Thanks
> ====
> 
> I would like to thank Yoann Vandoorselaere for his intensive work on
> the Prelude project and I would like to thank Daniel B. Cid for his
> rapid feedback to my existential questions over is data structure.
> _______________________________________________
> Prelude-devel site list
> [email protected]
> http://www.prelude-ids.org/mailman/listinfo/prelude-devel

_______________________________________________
Prelude-devel site list
[email protected]
http://www.prelude-ids.org/mailman/listinfo/prelude-devel
signature.asc (application/pgp-signature, 187 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.3 (FreeBSD)

iD8DBQFHCjX3Lh3hlgHmc7MRAvEkAJwMqPtJxwnbYZA5sGn0+dXJIwCImACgxwCC
u6Za/BDa9Y15U5rKAbhz2EE=
=vYrH
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.