Santiago Newbery is doing a trial and asked an important question about getting the data out once it has discovered everything. This is a great question, and it seemed good to share his question and answer with the mailing list.

Hi Santiago,

There are a few interfaces to the software:
    - We log to syslog
    - *assimcli query* ...         canned queries with flat ASCII output
*assimcli query list* -- queries the set of queries ;-)
    - REST interface giving the same queries but in more detail in JSON
- Neo4j queries of your own design - can easily be made into canned queries. - */usr/share/assimilation/notification.d* directory for scripts that get invoked to notify you of events

Note that the security issues are not yet events. For the near term, the assumption is that you would point your SIEM at our logs and give it a regex or two to look for. Note that we don't continually complain about anything. We complain once and that's it. When it's fixed, we note it once, and that's it.

A big part of the process for us is to learn what your interface needs are, and how we can most easily meet them. I can think of so many cool things you could do with the information we have. The question isn't what /I/ think is cool, it's what's useful to /you/.

There is currently a bug which would likely interfere with you adding new queries once the system is up. I found this shortly before I released it. It is a high priority to fix. https://trello.com/c/X4Cq0iUE

By the way, if you're so inclined, feel free to fix the docs and make github pull requests. Or just make Trello items, or github issues if you're not so inclined. https://github.com/assimilation/assimilation-official

    Many Thanks Santiago!

    -- Alan Robertson
[email protected]



On 09/30/2015 06:56 PM, Santiago Newbery wrote:
The documentation states to use

#service cma start

but for CentOS 7 that should be:

#systemctl start assimilation-cma

and

# systemctl start assimilation-nanoprobe

but now how to get output?



--Santiago


On Wed, Sep 30, 2015 at 12:10 PM, Alan Robertson <[email protected] <mailto:[email protected]>> wrote:

    Hi Santiago,

    Please give this a shot and get back to me. I'll be out of pocket
    on Thursday-Sunday morning.

    I've just built and tagged release 1.0.1. This is all based out of
    github - new source control, new build process and most
    importantly a shiny new /push-button installer/. This solves one
    of the main complaints from people who are working on trials with us!

    Use the same installer on any platform we provide packages for. No
    more dependency issues - no building from source for almost
    everyone. It just works. We now also provide builds for 10 (/count
    'em ten!/) 64-bit platforms:

      * Ubuntu precise, trusty, vivid, and wily.
      * Debian jessie and wheezy.
      * CentOS 6 and 7.
      * Fedora 21 and 22.

    The installer can be found at http://bit.ly/assiminstall

    An overview can be found here:
    
http://linux-ha.org/source-doc/assimilation/html/_getting_started.html#MagicInstallerOutline


    You can read the release description here:
    http://linux-ha.org/source-doc/assimilation/html/_release_descriptions.html
    or here:
    https://github.com/assimilation/assimilation-official/releases

    Coverity Analysis:

         Your request for analysis of Assimilation has been completed 
successfully.
         The results are available 
athttps://scan.coverity.com/projects/assimilation

         Analysis Summary:
            New defects found: 0
            Defects eliminated: 0

    That is, coverity can't find any defects. Clang says the same
    thing, but doesn't have a fancy reporting system ;-).

    Looking to hear how it works out for you!

        Enjoy!

        -- Alan Robertson
    [email protected] <mailto:[email protected]> OR
    [email protected] <mailto:[email protected]>
--
    Alan Robertson / CTO
    [email protected]
    <mailto:[email protected]>/ +1 303.947.7999
    <tel:%2B1%20303.947.7999>

    Assimilation Systems Limited
    http://AssimilationSystems.com

    Twitter <https://twitter.com/ossalanr> Linkedin
    <https://www.linkedin.com/in/alanr> skype
    <https://htmlsig.com/skype?username=alanr_unix.sh>




--

Alan Robertson / CTO
[email protected] <mailto:[email protected]>/ +1 303.947.7999

Assimilation Systems Limited
http://AssimilationSystems.com

Twitter <https://twitter.com/ossalanr> Linkedin <https://www.linkedin.com/in/alanr> skype <https://htmlsig.com/skype?username=alanr_unix.sh>



_______________________________________________
Assimilation mailing list - Discovery-Driven Monitoring
[email protected]
http://lists.community.tummy.com/cgi-bin/mailman/listinfo/assimilation
http://assimmon.org/

Reply via email to