I'm just getting started with ossec, slowly. For now I'm using it
solely for file integrity monitoring, for pci dss.

The only change I've made thus far is to write a small shell script to
send a consolidated report. It enumerates the list of active agents,
then queries each one to dump it's list of changed files. Then emails
it to the sysadmins to review.

Sent from my iPhone.

On Aug 19, 2010, at 19:57, jplee3 <[email protected]> wrote:

> All,
>
> I just wanted to get some ideas as to how you are leveraging OSSEC to
> meet PCI requirements.
>
> I understand that with the FIM, basically, OSSEC needs to be installed
> on the [monitored] servers/workstations for FIM to even work.
>
> However, I have a couple outstanding questions:
>
> 1) Would OSSEC technically satisfy req 11.4 - "use intrusion-detection
> systems..." - OSSEC is considered a HIDS isn't it? After reading
> through it more, it seems like they are looking for a system where
> there's a signature/rules engine that should be kept up-to-date of
> course. We have a NIDS deployed and I figure OSSEC HIDS would just
> supplement it, but not necessarily 'add' to the ability to satisfy req
> 11.4
>
> 2) I would assume 10.6 (daily review of logs) is covered by the fact
> that OSSEC analyzes log files in real-time and will alert, email, etc
> based on any triggers. Again, this sounds more like a 'supplemental'
> type of thing where you can't just say "Oh, OSSEC fulfills 10.6
> because it reads all the logs on a daily basis," right?
>
> On that note: in terms of centralizing logs, are a lot of you remote
> syslogging (in Linux... or using Snare i.e. for Windows) to a central
> log server(s) and running OSSEC on the central log server with the
> primary purpose of analyzing the syslogs as they flow in?
> I guess, in agent mode, it doesn't matter either way. My main thing
> here is that the logs need to be centralized, so even with an OSSEC
> server-agent model, I would still need to ship the syslogs off to a
> central location.
> I'm just trying to get a feel as to whether or not one way would be
> better than the other in terms of efficiency, etc.
>
>
> Any ideas/thoughts would be appreciated.
>
> TIA!!!
>

Reply via email to