Thanks for the info. It was helpful. 

Can the following be configured in OSSEC?



·        
Maintain 30 days worth of data on hand

·        
Past 30 days the data should be compressed and
archived for 30 days 

·        
After 60 days the data should be deleted


Alerting
based on requirements:

·        
Actual Alert based on specific patterns, key
words

·        
Actual Alert delivered via email, syslog, SMNP


Thanks,
Solomon Joshua

> Date: Mon, 24 Jan 2011 10:52:05 -0500
> Subject: Re: [ossec-list] Queries regarding OSSEC Syslog Collector
> From: [email protected]
> To: [email protected]
> 
> Hi Solomon,
> 
> On Mon, Jan 24, 2011 at 9:06 AM, Solomon Joshua <[email protected]> 
> wrote:
> > Hello,
> >
> > Can OSSEC aggregate and display the Syslogs from any device in one location?
> > Can the data be collected/displayed based on IP Address, Name, Part of
> > message, Lookup by device or by message (raw string search)?
> >
> > Thanks,
> > Solomon Joshua
> >
> 
> Check out the ossec-reportd application. It can do some of what you're
> looking for.
> Also tools like Splunk might be able to help.
                                          

Reply via email to