Using snare creates a drop point for logging because it does not
guarantee delivery (it just sends the messages and if they don't make it
snare does not care). I think using the ossec agent for windows is a
better choice for delivery. One big difference is that ossec will be
sending everything to the server and snare only sends the events
selected in the registry. Neither does a good job correlating logon
events since they are now fragmented. A single logon generates a ton of
logon events if auditing is fully engaged. I also noticed that with the
ossec windows agent there are important events that don't get flagged
(like terminal server logins).
On 01/10/2011 05:57 PM, dan (ddp) wrote:
On Mon, Jan 10, 2011 at 5:46 PM, NetSyphon<[email protected]> wrote:
Amazing! Now I just have to find a good front end for log mining and
relationship tracking similar to what the costly stuff does.
I would rather just invest in making ossec more like arcsight etc, not the
other way around :)
Splunk has some nice features.
On Mon, Jan 10, 2011 at 5:32 PM, dan (ddp)<[email protected]> wrote:
Hi Andy,
On Mon, Jan 10, 2011 at 5:18 PM, NetSyphon<[email protected]> wrote:
Hello List,
Does OSSEC do any sort of log replay on either windows or *nix, so that
if
an agent is stopped and started that it will "replay" to catch up? I'm
trying to prove that OSSEC is at least a better option than something
like
syslogd/SNARE/logparser for log centralization (and in many cases better
than overpriced and bloated solutions from vendors like arcsight, if
there
was only a more robust front end!).
TIA,
Andy
The agents keep track of where in the logfiles they stop. So if the
ossec processes were stopped and started again a while later they
should pick up where they left off.
--
R. Loyd Darby, OSSIM-OCSE
Project Manager DOC/NOAA/NMFS
Infrastructure coordinator
Southeast Fisheries Science Center
305-361-4297