Re: prelude-lml SNARE ruleset
Yoann Vandoorselaere <[email protected]> Mon, 23 Nov 2009 15:46:17 +0100
| Newsgroups | gmane.comp.security.ids.prelude.user |
|---|---|
| Message-ID | <1258987577.2230.36.camel@arwen> |
Hi Nicholas, Le jeudi 19 novembre 2009 à 10:37 -0600, Nicholas Nachefski a écrit : > Hello, > > I've created and tested a set of prelude-lml rules for use with SNARE on > Windows. This series of pcre regex captures important security event logs > and translates them into IDMEF for use with prelude-manager/prewikka. > > Make sure you disable the 'SYSLOG HEADERS' option in Snare or else the regex > wont match, or leave headers enabled and adjust the regex. The headers just > provide redundant information anyway on Windows. > > Let me know if you have any comments or questions. These have been tested > thoroughly, but any recommendations or feedback would be greatly > appreciated. Thank you very much for this contribution ! Could you please append, at the top of each rule, an example log that can be used to trigger the rule ? This is used for regression testing, and should have this format: #LOG:<exemple log entry> It will also help when reviewing contributed rules, to check whether each fields is assigned to the correct IDMEF element. Also, referring to the 'SYSLOG HEADERS' option, could you provides two logs for each rules, with and without the option enabled. This will allow us to check whether there is an easy way to make both kind of output supported, without duplicating the rules. Thanks again, -- Yoann Vandoorselaere | Directeur Technique/CTO | PreludeIDS Technologies Tel: +33 (0)8 70 70 21 58 Fax: +33(0)4 78 42 21 58 http://www.prelude-ids.com _______________________________________________ Prelude-user site list [email protected] http://lists.prelude-ids.org/mailman/listinfo/prelude-user