Re: prelude-lml SNARE ruleset

Yoann Vandoorselaere <[email protected]> Mon, 23 Nov 2009 15:46:17 +0100
Newsgroups gmane.comp.security.ids.prelude.user
Message-ID <1258987577.2230.36.camel@arwen>
Hi Nicholas,

Le jeudi 19 novembre 2009 à 10:37 -0600, Nicholas Nachefski a écrit :
> Hello,
> 
> I've created and tested a set of prelude-lml rules for use with SNARE on
> Windows.  This series of pcre regex captures important security event logs
> and translates them into IDMEF for use with prelude-manager/prewikka.
> 
> Make sure you disable the 'SYSLOG HEADERS' option in Snare or else the regex
> wont match, or leave headers enabled and adjust the regex.  The headers just
> provide redundant information anyway on Windows.
> 
> Let me know if you have any comments or questions.  These have been tested
> thoroughly, but any recommendations or feedback would be greatly
> appreciated.

Thank you very much for this contribution !

Could you please append, at the top of each rule, an example log that
can be used to trigger the rule ?

This is used for regression testing, and should have this format:
#LOG:<exemple log entry>

It will also help when reviewing contributed rules, to check whether
each fields is assigned to the correct IDMEF element.

Also, referring to the 'SYSLOG HEADERS' option, could you provides two
logs for each rules, with and without the option enabled. This will
allow us to check whether there is an easy way to make both kind of
output supported, without duplicating the rules.

Thanks again,

-- 
Yoann Vandoorselaere | Directeur Technique/CTO | PreludeIDS Technologies
Tel: +33 (0)8 70 70 21 58                       Fax: +33(0)4 78 42 21 58
http://www.prelude-ids.com


_______________________________________________
Prelude-user site list
[email protected]
http://lists.prelude-ids.org/mailman/listinfo/prelude-user