Splunk is nice but I had troubles getting it to work with the ossec plugin, may try again. It's also somewhat cost prohibitive since it's doing only a small portion of what it's needed for compared to ossec. I agree on the snare comparison, it's not practical for the security minded.
I think I'm just going to turn on the logall and replace my current syslog-ng, and continue efforts on getting some sort of front end that can show some sort of cross system correlation. On Jan 10, 2011, at 23:24, "loyd. darby" <[email protected]> wrote: > Using snare creates a drop point for logging because it does not guarantee > delivery (it just sends the messages and if they don't make it snare does not > care). I think using the ossec agent for windows is a better choice for > delivery. One big difference is that ossec will be sending everything to the > server and snare only sends the events selected in the registry. Neither > does a good job correlating logon events since they are now fragmented. A > single logon generates a ton of logon events if auditing is fully engaged. I > also noticed that with the ossec windows agent there are important events > that don't get flagged (like terminal server logins). > > On 01/10/2011 05:57 PM, dan (ddp) wrote: >> On Mon, Jan 10, 2011 at 5:46 PM, NetSyphon<[email protected]> wrote: >>> Amazing! Now I just have to find a good front end for log mining and >>> relationship tracking similar to what the costly stuff does. >>> I would rather just invest in making ossec more like arcsight etc, not the >>> other way around :) >>> >> Splunk has some nice features. >> >> >>> On Mon, Jan 10, 2011 at 5:32 PM, dan (ddp)<[email protected]> wrote: >>>> Hi Andy, >>>> >>>> On Mon, Jan 10, 2011 at 5:18 PM, NetSyphon<[email protected]> wrote: >>>>> Hello List, >>>>> Does OSSEC do any sort of log replay on either windows or *nix, so that >>>>> if >>>>> an agent is stopped and started that it will "replay" to catch up? I'm >>>>> trying to prove that OSSEC is at least a better option than something >>>>> like >>>>> syslogd/SNARE/logparser for log centralization (and in many cases better >>>>> than overpriced and bloated solutions from vendors like arcsight, if >>>>> there >>>>> was only a more robust front end!). >>>>> >>>>> TIA, >>>>> Andy >>>>> >>>>> >>>> The agents keep track of where in the logfiles they stop. So if the >>>> ossec processes were stopped and started again a while later they >>>> should pick up where they left off. >>> > > -- > R. Loyd Darby, OSSIM-OCSE > Project Manager DOC/NOAA/NMFS > Infrastructure coordinator > Southeast Fisheries Science Center > 305-361-4297 >
