Re: Undefinied alert defnitions
Steve Grubb <[email protected]>
| Newsgroups | gmane.comp.security.ids.prelude.user |
|---|---|
| Message-ID | <[email protected]> |
On Tuesday 05 February 2008 11:08:48 Sebastien Tricaud wrote: > > That's what I thought, but on the other hand if I don't do that there is > > a risk of missing an event that I am not expecting. You can not really > > define a rule for every single alert that a particular device might > > throw at you. I was wondering if there'd be a way to generically > > classify unmatched alerts and submit them to the database, since an > > unclassified event is still an event... > > Prelude LML vocation is not to replace software like syslog-ng. But to > find specific patterns to create an IDMEF alert. > For database logging, I'd really advice you to go for syslog-ng. Or maybe give rsyslog a looking at. We've added gssapi support for trusted logging. It can use a SQL backend, it does realtime event classification via regex, and uses the familiar sysklogd configuration syntax. -Steve _______________________________________________ Prelude-user site list [email protected] http://www.prelude-ids.org/mailman/listinfo/prelude-user