This is a good idea as well, assuming the Commercial product can poll events (i.e. RSA Envision, etc). Most products should be able to poll. Running a proprietary agent + the OSSEC agent could potentially cause performance issues and is generally looked down upon as it adds another layer of management. But the FIM aspects OSSEC offers makes it worthwhile installing on any critical server. Yes, certain aspects could be polished on it, but it's the best *free* solution out there that I've come across.
On Mon, Jan 24, 2011 at 4:11 PM, Jefferson, Shawn < [email protected]> wrote: > Hi, > > I think you are probably better off getting your Commerical product to > query/collect the Windows event logs itself. You can use OSSEC for a second > layer of detection on the event logs, as well as utilize the other features. > > -----Original Message----- > From: [email protected] [mailto:[email protected]] On > Behalf Of ash kumar > Sent: Monday, January 24, 2011 1:35 PM > To: ossec-list > Subject: [ossec-list] Forwarding Logs to Commercial Log Management Systems > > I would like to forward some of the logs (MS Event Logs) to another Log > management appliance. > > This problem breaks down into two parts. > 1. Selectively forward syslogs --> This is easily configured in ossec.conf > 2. Strip ossec specific parts of the log and forward the rest to the log > management appliance which can parse native Event Logs. > > It is the second part that I have not been able to figure out. I suspect > this would involve a perl script stripping and forwarding the logs. > has anyone tried this? > > Thanks > > Ash >
