Prelude alert workflow

Christopher Byrd <[email protected]> Sun, 29 Nov 2009 23:03:20 -0600
Newsgroups gmane.comp.security.ids.prelude.user
Message-ID <[email protected]>
I have set up a working lab for Prelude combined with OSSEC and Snort
using the open source version of Prelude.  My question for the list is
how are you actually using Prelude in production?  What workflow do
you use to review and respond to alerts, especially in multi-analyst
environments?

Using Prewikka (not Pro) the only method I can find to "handle" an
event is to delete it, which I have confirmed will delete the alert
entirely from the database.  This would seem to make auditing for
review and compliance activities difficult.  In my case, I'd like to
find a way to mark the alert as reviewed, hopefully including an
optional comment or classification.  Preferably, reviewed alerts would
be archived in the database, and only available in reports, or when
defined in searches, etc.

It may be that the ticket system in Prewikka Pro is the answer,
although I still wonder if even the automatic ticket system fully
answers the above.  I'm hoping someone has some insight on how this
works in the open source version, if it is possible at all.

If you are using Prelude/Prewikka in production would you please
comment on how you use it as part of your processes?

Thanks in advance!

Christopher
_______________________________________________
Prelude-user site list
[email protected]
http://lists.prelude-ids.org/mailman/listinfo/prelude-user