Re: open source artificial ignorance-like systems
James Turnbull <[email protected]>
| Newsgroups | gmane.comp.sysutils.loganalysis |
|---|---|
| Message-ID | <[email protected]> |
> assets to white list, black list, etc.). But to answer the OP's > question, none of the good stuff is open source. You can check out > OSSEC which does some correlation between different types of events. Tom With all due respect I think that's incorrect. Both Anton and myself mentioned SEC, others have mentioned their FOSS log tool of choice and there are numerous others - Swatch and OSSIM both spring to mind. If I compare netForensics or Intellitactics with SEC - you know what the primary difference is? A pretty front-end and perhaps some scalability. The core functionality is fairly similar. And in terms of usability - well how many hours of implementation and management could you buy for the purchase price and maintenance charges of most commercial event managers? I've used both commercial and open source tools and think that event correlation/management tools are better assessed on the merits of their functionality rather than their purchase price. Regards James Turnbull -- James Turnbull <[email protected]> --- Author of Pro Nagios 2.0 (http://www.amazon.com/gp/product/1590596099/) Hardening Linux (http://www.amazon.com/gp/product/1590594444/) --- PGP Key (http://pgp.mit.edu:11371/pks/lookup?op=get&search=0x0C42DF40) _______________________________________________ LogAnalysis mailing list [email protected] http://www.loganalysis.org/mailman/listinfo/loganalysis
signature.asc
(application/pgp-signature, 250 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFGJZCO9hTGvAxC30ARCAofAKCLO8z58OtlPq08e1ryj2AxaaFFOACglUs/ mjIBP4jKtMa1sGl2ljuozqc= =+kIG -----END PGP SIGNATURE-----