Re: Undefinied alert defnitions

Steve Grubb <[email protected]>
Newsgroups gmane.comp.security.ids.prelude.user
Message-ID <[email protected]>
On Tuesday 05 February 2008 11:08:48 Sebastien Tricaud wrote:
> > That's what I thought, but on the other hand if I don't do that there is
> > a risk of missing an event that I am not expecting. You can not really
> > define a rule for every single alert that a particular device might
> > throw at you. I was wondering if there'd be a way to generically
> > classify unmatched alerts and submit them to the database, since an
> > unclassified event is still an event...
>
> Prelude LML vocation is not to replace software like syslog-ng. But to
> find specific patterns to create an IDMEF alert.
> For database logging, I'd really advice you to go for syslog-ng.

Or maybe give rsyslog a looking at. We've added gssapi support for trusted 
logging. It can use a SQL backend, it does realtime event classification via 
regex, and uses the familiar sysklogd configuration syntax.

-Steve
_______________________________________________
Prelude-user site list
[email protected]
http://www.prelude-ids.org/mailman/listinfo/prelude-user
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.