Hi, Of course your SIEM needs to "understand" the OSSEC logs. I use Envision and it's very easy to do this with Event Source Integrator.
-- Shawn ________________________________ From: [email protected] [mailto:[email protected]] On Behalf Of tanishk lakhaani Sent: Friday, February 04, 2011 10:27 AM To: [email protected] Subject: Re: [ossec-list] Forwarding Logs to Commercial Log Management Systems Hi, Probably this is Ok, but dnt u think that some changes have to be done at the SIEM side as well, to accept the syslogs from the OSSEC Server. Regards Tanishk On Thu, Feb 3, 2011 at 3:14 AM, Jefferson, Shawn <[email protected]<mailto:[email protected]>> wrote: Hi, It depends on what you are trying to do I guess. Here's how I have it setup: 1. Set the syslog output in the ossec.conf <syslog_output> <server>196.168.1.1</server> </syslog_output> 2. Optionally set syslog on the server itself to send messages to your SIEM (just like you would with any server.) ________________________________ From: [email protected]<mailto:[email protected]> [mailto:[email protected]<mailto:[email protected]>] On Behalf Of tanishk lakhaani Sent: Wednesday, February 02, 2011 12:15 PM To: [email protected]<mailto:[email protected]> Subject: Re: [ossec-list] Forwarding Logs to Commercial Log Management Systems Hi all, Lets say that I want to forward the logs of an OSSEC Server, to a commercial SIEM. So, in that case how can I install OSSEC agent to forward all logs to SIEM. Also, what we shud do is Step1: Modify the syslog.conf of the OSSEC Server, and redierct all the logs in the /var/log/messages and /var/log/authlog etc to local7 utility, and from that local7 utility, we shud forward the logs to the SIEM IP. It is sth like this: /var/log/messages <tab_space> local7.* /var/log/authlog <tab_space> local7.* local7.* <tab_space> @SIEM_IP I am not sure that whether it will work or not. Pls correct me if I am wrong Regards Tanishk On Tue, Feb 1, 2011 at 9:28 PM, ash kumar <[email protected]<mailto:[email protected]>> wrote: Mike, > I would like to forward some of the logs (MS Event Logs) to another > Log management appliance. You have a few options here. You can use something like Snare, which can selectively forward logs, or you can use the OSSEC agent to forward all logs and then send only some of them into the SIEM. There are several other options for forwarding logs to a commercial SIEM including onee natively provided by the manufacturer. However, there is a lot of additional value in the OSSEC agent (including file integrity, Intrusion detection rules, categorizing alerts etc.,) that can not be supplemented. Having multiple agents on each server is not worth the processing, network overhead cost and I believe being able to use the ossec agent is a very elegent and comprehensive solution ( I would add wmi queries to the rules engine though). I have ditched Snare in favor of ossec agents actually. > This problem breaks down into two parts. > 1. Selectively forward syslogs --> This is easily configured in > ossec.conf Well, to be clear: when you do this in OSSEC, you're really forwarding alerts. Do you want to send raw logs or alerts? Raw logs actually, because I can handle alerts quite elegantly by email. Raw logs forwarded to a SIEM allows me to archive data, carry out trending analysis and periodic reporting well. > 2. Strip ossec specific parts of the log and forward the rest to the > log management appliance which can parse native Event Logs. I have done this with syslog-ng. I never completed it fully but when/if I do I will post a how-to. That is a good idea. I will try it too. Thanks for your time and attention Ash Kumar -- warm regards Tanishk Lakhaani -- warm regards Tanishk Lakhaani
