Splunk is nice but I had troubles getting it to work with the ossec plugin, may 
try again. It's also somewhat cost prohibitive since it's doing only a small 
portion of what it's needed for compared to ossec.  I agree on the snare 
comparison, it's not practical for the security minded. 

I think I'm just going to turn on the logall and replace my current syslog-ng, 
and continue efforts on getting some sort of front end that can show some sort 
of cross system correlation. 

On Jan 10, 2011, at 23:24, "loyd. darby" <[email protected]> wrote:

> Using snare creates a drop point for logging because it does not guarantee 
> delivery (it just sends the messages and if they don't make it snare does not 
> care).  I think using the ossec agent for windows is a better choice for 
> delivery.  One big difference is that ossec will be sending everything to the 
> server and snare only sends the events selected in the registry.  Neither 
> does a good job correlating logon events since they are now fragmented.  A 
> single logon generates a ton of logon events if auditing is fully engaged.  I 
> also noticed that with the ossec windows agent there are important events 
> that don't get flagged (like terminal server logins).
> 
> On 01/10/2011 05:57 PM, dan (ddp) wrote:
>> On Mon, Jan 10, 2011 at 5:46 PM, NetSyphon<[email protected]> wrote:
>>> Amazing!  Now I just have to find a good front end for log mining and
>>> relationship tracking similar to what the costly stuff does.
>>> I would rather just invest in making ossec more like arcsight etc, not the
>>> other way around :)
>>> 
>> Splunk has some nice features.
>> 
>> 
>>> On Mon, Jan 10, 2011 at 5:32 PM, dan (ddp)<[email protected]>  wrote:
>>>> Hi Andy,
>>>> 
>>>> On Mon, Jan 10, 2011 at 5:18 PM, NetSyphon<[email protected]>  wrote:
>>>>> Hello List,
>>>>> Does OSSEC do any sort of log replay on either windows or *nix, so that
>>>>> if
>>>>> an agent is stopped and started that it will "replay" to catch up?  I'm
>>>>> trying to prove that OSSEC is at least a better option than something
>>>>> like
>>>>> syslogd/SNARE/logparser for log centralization (and in many cases better
>>>>> than overpriced and bloated solutions from vendors like arcsight, if
>>>>> there
>>>>> was only a more robust front end!).
>>>>> 
>>>>> TIA,
>>>>> Andy
>>>>> 
>>>>> 
>>>> The agents keep track of where in the logfiles they stop. So if the
>>>> ossec processes were stopped and started again a while later they
>>>> should pick up where they left off.
>>> 
> 
> -- 
> R. Loyd Darby, OSSIM-OCSE
> Project Manager DOC/NOAA/NMFS
> Infrastructure coordinator
> Southeast Fisheries Science Center
> 305-361-4297
> 

Reply via email to