What SIEM are you using? Also, this may be obvious, but make sure the SIEM
is setup/enabled to receive syslogs from other sources (a lot of SIEMS use
agents to poll data but will also have syslog receive functionality).You'll
probably have to make sure that the server where you're forwarding logs from
is forwarding using the right facility/severity as well. Unless the SIEM has
the ability to change those parameters.



On Fri, Feb 4, 2011 at 10:27 AM, tanishk lakhaani <[email protected]>wrote:

> Hi,
> Probably this is Ok, but dnt u think that some changes have to be done at
> the SIEM side as well, to accept the syslogs from the OSSEC Server.
>
> Regards
> Tanishk
>
> On Thu, Feb 3, 2011 at 3:14 AM, Jefferson, Shawn <
> [email protected]> wrote:
>
>>  Hi,
>>
>> It depends on what you are trying to do I guess.  Here's how I have it
>> setup:
>>
>> 1. Set the syslog output in the ossec.conf
>>
>>   <syslog_output>
>>     <server>196.168.1.1</server>
>>   </syslog_output>
>>
>> 2. Optionally set syslog on the server itself to send messages to your
>> SIEM (just like you would with any server.)
>>
>>
>>
>>  ------------------------------
>> *From:* [email protected] [mailto:[email protected]]
>> *On Behalf Of *tanishk lakhaani
>> *Sent:* Wednesday, February 02, 2011 12:15 PM
>> *To:* [email protected]
>> *Subject:* Re: [ossec-list] Forwarding Logs to Commercial Log Management
>> Systems
>>
>>   Hi all,
>> Lets say that I want to forward the logs of an OSSEC Server, to a
>> commercial SIEM. So, in that case how can I install OSSEC agent to forward
>> all logs to SIEM.
>>
>> Also, what we shud do is
>> Step1: Modify the syslog.conf of the OSSEC Server, and redierct all the
>> logs in the /var/log/messages and /var/log/authlog etc to local7 utility,
>> and from that local7 utility, we shud forward the logs to the SIEM IP. It is
>> sth like this:
>>
>> /var/log/messages <tab_space> local7.*
>>  /var/log/authlog <tab_space> local7.*
>>
>> local7.* <tab_space> @SIEM_IP
>>
>> I am not sure that whether it will work or not. Pls correct me if I am
>> wrong
>>
>> Regards
>> Tanishk
>>
>>
>>
>> On Tue, Feb 1, 2011 at 9:28 PM, ash kumar <[email protected]> wrote:
>>
>>> Mike,
>>>
>>>  > I would like to forward some of the logs (MS Event Logs) to another
>>> > Log management appliance.
>>>
>>> You have a few options here. You can use something like Snare, which can
>>> selectively forward logs, or you can use the OSSEC agent to forward all
>>> logs and then send only some of them into the SIEM.
>>>
>>> There are several other options for forwarding logs to a commercial SIEM
>>> including onee natively provided by the manufacturer. However, there is a
>>> lot of additional value in the OSSEC agent (including file integrity,
>>> Intrusion detection rules, categorizing alerts etc.,) that can not be
>>> supplemented. Having multiple agents on each server is not worth the
>>> processing, network overhead cost and I believe being able to use the ossec
>>> agent is a very elegent and comprehensive solution ( I would add wmi queries
>>> to the rules engine though). I have ditched Snare in favor of ossec agents
>>> actually.
>>>
>>> > This problem breaks down into two parts.
>>> > 1. Selectively forward syslogs -->  This is easily configured in
>>> > ossec.conf
>>>
>>> Well, to be clear: when you do this in OSSEC, you're really forwarding
>>> alerts. Do you want to send raw logs or alerts?
>>>
>>> Raw logs actually, because I can handle alerts quite elegantly by email.
>>> Raw logs forwarded to a SIEM allows me to archive data, carry out trending
>>> analysis and periodic reporting well.
>>>
>>> > 2. Strip ossec specific parts of the log and forward the rest to the
>>> > log management appliance which can parse native Event Logs.
>>>
>>> I have done this with syslog-ng. I never completed it fully but when/if
>>> I do I will post a how-to.
>>>
>>> That is a good idea. I will try it too.
>>>
>>>
>>> Thanks for your time and attention
>>>
>>>
>>> Ash Kumar
>>>
>>>
>>>
>>
>>
>> --
>> warm regards
>> Tanishk Lakhaani
>>
>
>
>
> --
> warm regards
> Tanishk Lakhaani
>

Reply via email to