Jeremy
I am using OSSIM for the same.

Any suggestions ?

Rgds
Tanishk

On Sat, Feb 5, 2011 at 12:26 AM, Jeremy Lee <[email protected]> wrote:

> What SIEM are you using? Also, this may be obvious, but make sure the SIEM
> is setup/enabled to receive syslogs from other sources (a lot of SIEMS use
> agents to poll data but will also have syslog receive functionality).You'll
> probably have to make sure that the server where you're forwarding logs from
> is forwarding using the right facility/severity as well. Unless the SIEM has
> the ability to change those parameters.
>
>
>
> On Fri, Feb 4, 2011 at 10:27 AM, tanishk lakhaani 
> <[email protected]>wrote:
>
>> Hi,
>> Probably this is Ok, but dnt u think that some changes have to be done at
>> the SIEM side as well, to accept the syslogs from the OSSEC Server.
>>
>> Regards
>> Tanishk
>>
>>  On Thu, Feb 3, 2011 at 3:14 AM, Jefferson, Shawn <
>> [email protected]> wrote:
>>
>>>  Hi,
>>>
>>> It depends on what you are trying to do I guess.  Here's how I have it
>>> setup:
>>>
>>> 1. Set the syslog output in the ossec.conf
>>>
>>>   <syslog_output>
>>>     <server>196.168.1.1</server>
>>>   </syslog_output>
>>>
>>> 2. Optionally set syslog on the server itself to send messages to your
>>> SIEM (just like you would with any server.)
>>>
>>>
>>>
>>>  ------------------------------
>>> *From:* [email protected] [mailto:[email protected]]
>>> *On Behalf Of *tanishk lakhaani
>>> *Sent:* Wednesday, February 02, 2011 12:15 PM
>>> *To:* [email protected]
>>> *Subject:* Re: [ossec-list] Forwarding Logs to Commercial Log Management
>>> Systems
>>>
>>>   Hi all,
>>> Lets say that I want to forward the logs of an OSSEC Server, to a
>>> commercial SIEM. So, in that case how can I install OSSEC agent to forward
>>> all logs to SIEM.
>>>
>>> Also, what we shud do is
>>> Step1: Modify the syslog.conf of the OSSEC Server, and redierct all the
>>> logs in the /var/log/messages and /var/log/authlog etc to local7 utility,
>>> and from that local7 utility, we shud forward the logs to the SIEM IP. It is
>>> sth like this:
>>>
>>> /var/log/messages <tab_space> local7.*
>>>  /var/log/authlog <tab_space> local7.*
>>>
>>> local7.* <tab_space> @SIEM_IP
>>>
>>> I am not sure that whether it will work or not. Pls correct me if I am
>>> wrong
>>>
>>> Regards
>>> Tanishk
>>>
>>>
>>>
>>> On Tue, Feb 1, 2011 at 9:28 PM, ash kumar <[email protected]> wrote:
>>>
>>>> Mike,
>>>>
>>>>  > I would like to forward some of the logs (MS Event Logs) to another
>>>> > Log management appliance.
>>>>
>>>> You have a few options here. You can use something like Snare, which
>>>> can
>>>> selectively forward logs, or you can use the OSSEC agent to forward all
>>>> logs and then send only some of them into the SIEM.
>>>>
>>>> There are several other options for forwarding logs to a commercial SIEM
>>>> including onee natively provided by the manufacturer. However, there is a
>>>> lot of additional value in the OSSEC agent (including file integrity,
>>>> Intrusion detection rules, categorizing alerts etc.,) that can not be
>>>> supplemented. Having multiple agents on each server is not worth the
>>>> processing, network overhead cost and I believe being able to use the ossec
>>>> agent is a very elegent and comprehensive solution ( I would add wmi 
>>>> queries
>>>> to the rules engine though). I have ditched Snare in favor of ossec agents
>>>> actually.
>>>>
>>>> > This problem breaks down into two parts.
>>>> > 1. Selectively forward syslogs -->  This is easily configured in
>>>> > ossec.conf
>>>>
>>>> Well, to be clear: when you do this in OSSEC, you're really forwarding
>>>> alerts. Do you want to send raw logs or alerts?
>>>>
>>>> Raw logs actually, because I can handle alerts quite elegantly by email.
>>>> Raw logs forwarded to a SIEM allows me to archive data, carry out trending
>>>> analysis and periodic reporting well.
>>>>
>>>> > 2. Strip ossec specific parts of the log and forward the rest to the
>>>> > log management appliance which can parse native Event Logs.
>>>>
>>>> I have done this with syslog-ng. I never completed it fully but when/if
>>>> I do I will post a how-to.
>>>>
>>>> That is a good idea. I will try it too.
>>>>
>>>>
>>>> Thanks for your time and attention
>>>>
>>>>
>>>> Ash Kumar
>>>>
>>>>
>>>>
>>>
>>>
>>> --
>>> warm regards
>>> Tanishk Lakhaani
>>>
>>
>>
>>
>> --
>> warm regards
>> Tanishk Lakhaani
>>
>
>


-- 
warm regards
Tanishk Lakhaani

Reply via email to