Prelude alert workflow
Christopher Byrd <[email protected]> Sun, 29 Nov 2009 23:03:20 -0600
| Newsgroups | gmane.comp.security.ids.prelude.user |
|---|---|
| Message-ID | <[email protected]> |
I have set up a working lab for Prelude combined with OSSEC and Snort using the open source version of Prelude. My question for the list is how are you actually using Prelude in production? What workflow do you use to review and respond to alerts, especially in multi-analyst environments? Using Prewikka (not Pro) the only method I can find to "handle" an event is to delete it, which I have confirmed will delete the alert entirely from the database. This would seem to make auditing for review and compliance activities difficult. In my case, I'd like to find a way to mark the alert as reviewed, hopefully including an optional comment or classification. Preferably, reviewed alerts would be archived in the database, and only available in reports, or when defined in searches, etc. It may be that the ticket system in Prewikka Pro is the answer, although I still wonder if even the automatic ticket system fully answers the above. I'm hoping someone has some insight on how this works in the open source version, if it is possible at all. If you are using Prelude/Prewikka in production would you please comment on how you use it as part of your processes? Thanks in advance! Christopher _______________________________________________ Prelude-user site list [email protected] http://lists.prelude-ids.org/mailman/listinfo/prelude-user