Re: Open Source centralized log management/SIEM solutions
Harry Hoffman <[email protected]> Mon, 26 Apr 2010 13:49:05 -0400
| Newsgroups | gmane.comp.sysutils.loganalysis |
|---|---|
| Message-ID | <[email protected]> |
What about octopussy? It's free, and perl http://www.8pussy.org/doku.php Cheers, Harry Sandy Bird wrote: > Wow, people still use this list? I think the last post was from Anton=20 > back at the first of the year. >=20 > =20 >=20 > Honestly, assuming you want true open source, it will be a struggle. =20 > OSSIM (now AlienVault) is as close as you can probably get. I would=20 > guess it is becoming more =93free=94 and less opensource by the day. I= f you=20 > are looking for =93free=94 and not open source you have a few additiona= l=20 > options. We have QRadar Slim Free Edition, but the free version is onl= y=20 > good to 50 EPS=85 After 50 EPS you have to purchase appliances and=20 > licenses. The alerting and most of the correlation still works in the=20 > free version, but you lose the offense manager as well as asset and=20 > identity tracking. Splunk is another option (although might be a=20 > struggle for some of your alerting), and again the free version limits=20 > the amount of data you can deal with, or you have to purchase licenses.= =20 >=20 > =20 >=20 > Syslog-ng, grep and perl are always an option J=85 only half joking her= e=85 >=20 > =20 >=20 > Sandy >=20 > =20 >=20 > *From:* [email protected]=20 > [mailto:[email protected]] *On Behalf Of *Youngquist,= =20 > Jason R. > *Sent:* Monday, April 26, 2010 12:04 PM > *To:* '[email protected]' > *Subject:* [logs] Open Source centralized log management/SIEM solutions >=20 > =20 >=20 > Is anyone using any Open Source or low cost centralized log=20 > management/SIEM solution in a production environment which you would=20 > recommend? >=20 > =20 >=20 > Specifically, I'm looking for: >=20 > --scalability - must be able to handle hundreds of log sources -=20 > majority being servers and network devices >=20 > --good searching capability >=20 > --ability to generate alerts >=20 > --good reporting capability =96 pre-built reports would be nice >=20 > --a solution auditors would approve >=20 > --able to meet regulatory requirements such as PCI >=20 > --fast implementation time =96 how long would it take to get the soluti= on=20 > up and running? >=20 > =20 >=20 > =20 >=20 > There are more things I=92d like, but these are the big requirements. >=20 > =20 >=20 > =20 >=20 > If an Open Source solution, are there any companies that offer=20 > professional services (ie. consulting/configuration assistance) so we=20 > could hit the ground running and not have to spend weeks/months=20 > configuring/creating rules/reports, etc. Ideally, the solution should=20 > have some commercial support behind it so if we run into any issues we=20 > can speak to a knowledgeable person. >=20 > =20 >=20 > =20 >=20 > For those QSAs out there, are there any Open Source solutions/low-cost=20 > solutions that you have seen implemented well and meet the PCI=20 > regulatory guidelines? If so, what were they? If not, what were they=20 > lacking that commercial products provide? >=20 > =20 >=20 > =20 >=20 > For those of you with a home-grown/Open Source log management solution,= =20 > do you agree with the Gartner quote below? Why/why not?=20 >=20 > According to Gartner researchers, "Although [home-grown log management]= =20 > may prove effective for a limited set of data sources with clearly=20 > defined "strings" that the organization is searching for, most=20 > organizations quickly run into scalability issues, as well as issues=20 > using the data for situational awareness in support of incident=20 > response. In most cases, internally developed centralized application=20 > log solutions will fall short of meeting organizational requirements." >=20 > =20 >=20 > If you had to do it again would you =93roll your own solution=94 or pur= chase=20 > a commercial log management product? >=20 > =20 >=20 > =20 >=20 > Appreciate any information you can provide. >=20 > =20 >=20 > =20 >=20 > Thanks. >=20 > Jason Youngquist >=20 > Information Technology Security Engineer, Security+ >=20 > Technology Services >=20 > Columbia College >=20 > 1001 Rogers Street, Columbia, MO 65216 >=20 > (573) 875-7334 >=20 > [email protected] >=20 > http://www.ccis.edu >=20 > =20 >=20 > =20 >=20 >=20 > -----------------------------------------------------------------------= - >=20 > _______________________________________________ > LogAnalysis mailing list > [email protected] > http://www.loganalysis.org/mailman/listinfo/loganalysis