Using snare creates a drop point for logging because it does not guarantee delivery (it just sends the messages and if they don't make it snare does not care). I think using the ossec agent for windows is a better choice for delivery. One big difference is that ossec will be sending everything to the server and snare only sends the events selected in the registry. Neither does a good job correlating logon events since they are now fragmented. A single logon generates a ton of logon events if auditing is fully engaged. I also noticed that with the ossec windows agent there are important events that don't get flagged (like terminal server logins).

On 01/10/2011 05:57 PM, dan (ddp) wrote:
On Mon, Jan 10, 2011 at 5:46 PM, NetSyphon<[email protected]>  wrote:
Amazing!  Now I just have to find a good front end for log mining and
relationship tracking similar to what the costly stuff does.
I would rather just invest in making ossec more like arcsight etc, not the
other way around :)

Splunk has some nice features.


On Mon, Jan 10, 2011 at 5:32 PM, dan (ddp)<[email protected]>  wrote:
Hi Andy,

On Mon, Jan 10, 2011 at 5:18 PM, NetSyphon<[email protected]>  wrote:
Hello List,
Does OSSEC do any sort of log replay on either windows or *nix, so that
if
an agent is stopped and started that it will "replay" to catch up?  I'm
trying to prove that OSSEC is at least a better option than something
like
syslogd/SNARE/logparser for log centralization (and in many cases better
than overpriced and bloated solutions from vendors like arcsight, if
there
was only a more robust front end!).

TIA,
Andy


The agents keep track of where in the logfiles they stop. So if the
ossec processes were stopped and started again a while later they
should pick up where they left off.


--
R. Loyd Darby, OSSIM-OCSE
Project Manager DOC/NOAA/NMFS
Infrastructure coordinator
Southeast Fisheries Science Center
305-361-4297

Reply via email to