Re: Prelude support for Ossec
Robin Gruyters <[email protected]>
| Newsgroups | gmane.comp.security.ids.prelude.devel |
|---|---|
| Message-ID | <[email protected]> |
Sebastien, Great to see that OSSEC is going to support Prelude Framework. Altough I'd encounter a problem when trying to install it. I'd run 'make setprelude' in the src/ tree, and I can see that I have the following entries in my Config.OS file: CEXTRA= -DDEFAULTDIR=\"/var/ossec\" -DLOCAL DEXTRA=-DUSE_OPENSSL TEXTRA=-pthread CPRELUDE=-DPRELUDE -I/usr/local/include When I run './install.sh' from the root installation dir. I noticed that the Config.OS gets overwritten, just before it starts to compile. At the moment I have done it manually, but I think/hope this will be fixed in the next (beta) release. Kind regards, -- Robin Gruyters Network and Security Engineer YIRDIS - Betronic Services I: http://yirdis.com I: http://betronic.nl P: +31 (0)20 5659191 F: +31 (0)20 5659190 On Sun, Oct 07, 2007 at 10:50:11PM +0200, Sebastien Tricaud wrote: > Hello people, > > I am happy the announce the prelude support in the upcoming Ossec release. > > > What is it? > ====== > > OSSEC is an Open Source Host-based Intrusion Detection System. It > performs log analysis, integrity checking, Windows registry > monitoring, rootkit detection, real-time alerting and active response. > > > Download it! > ======== > > The prelude code is currently in CVS, but you can get a nightly snapshot here : > http://www.ossec.net/files/snapshots/ossec-hids-071006.tar.gz > > > Compile it! > ====== > > You must go into the src/ directory and type "make setprelude". Then > you can go back to the sources root and run the "install.sh" script. > Since this is beta, that's how you should do it, things will be easier > for the official release (simple question such as "do you want to > enable prelude support ?"). > > > Install it! > ===== > > It is installed just like a regular sensor (intructions -> > https://trac.prelude-ids.org/wiki/RegisteringASensor). > > Two *important* things to keep in mind : > * When performing registration, the "Ossec" group and user must be > registered instead of root, since Prelude code runs as part of the > analysis section of the Ossec program. And Ossec runs this code under > both ossec user and group. > * In the configuration file "ossec.conf", you should add the following > line in the <global> section : > <prelude_output>yes</prelude_output> > > > Issues > ==== > > IDMEF Messages are not as full as I would like them to be, this is > because I live in Paris, which is a very fun city to be in, and there > are a lot outdoors activities that I do here. I promise to reduce my > social activities to have something more exhaustive. > > Thanks > ==== > > I would like to thank Yoann Vandoorselaere for his intensive work on > the Prelude project and I would like to thank Daniel B. Cid for his > rapid feedback to my existential questions over is data structure. > _______________________________________________ > Prelude-devel site list > [email protected] > http://www.prelude-ids.org/mailman/listinfo/prelude-devel _______________________________________________ Prelude-devel site list [email protected] http://www.prelude-ids.org/mailman/listinfo/prelude-devel
signature.asc
(application/pgp-signature, 187 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.3 (FreeBSD) iD8DBQFHCjX3Lh3hlgHmc7MRAvEkAJwMqPtJxwnbYZA5sGn0+dXJIwCImACgxwCC u6Za/BDa9Y15U5rKAbhz2EE= =vYrH -----END PGP SIGNATURE-----