DK 'Log


OSSEC 2.0 going public...
Fri, 27 Feb 2009

Cheering at Daniel & co. for their ossec 2.0 release.
I'm actually very excited about this new release (agentless monitoring being my favourite) and the moment is perfect: I'll put this into the installer beta right away and make it avaiable along ossim asap.

Congratulations :-)

posted at: 20:53 | path: /friends | permanent link to this entry | 0 comments |
Tags: ossec



Tutorial 5: Windows event logging
Wed, 19 Dec 2007

The windows event log

As an introduction to windows event logging I recommend reading the following article: Monitoring and Troubleshooting Using Event Logs. It's the first interesting one I've found after googling for an introduction.

Quoting the article, which also talks about EventCombMT.exe which we'll mention later:

This article reviews best practices for working with Windows event logs including how to interpret 
event messages, how to configure event logs, how to search and filter events, how to view events on 
remote systems, and how to use EventCombMT.exe and other tools to monitor events on multiple systems.


::read more

posted at: 15:54 | path: /ossim/tutorials | permanent link to this entry | 12 comments |
Tags: ossim, snare, ossec, compliance, eventlog



Installer updates.
Sat, 24 Nov 2007

Let's get a first meaningful update running too.

We have been working hard these last weeks to get the installer out and polish some outstanding issues. After the initial releases, our priorities are now focused on:

  • Get an updater done (will be included with 1.0.4)
  • Fix some remaining issues (two persons have reported hangs at specific OS installation stages)
  • Allow for easy installation of specific graph plugins depending on scenario (ISO, Inventory, Nessus, etc...)
This last point has been evolving a lot and adding new custom graphs to the panel is as easy as ever. Check the screens below (once I've got them uploaded :-) ).

In the meantime, we preinstalled OSSEC (thanks Daniel for your help), fixed the Nagios plugin, fixed rrd_plugin which was missing a config line and added Munin to the sensor pages for performance monitorization.

posted at: 21:21 | path: /ossim/installer | permanent link to this entry | 5 comments |
Tags: ossim, installer, graphs, ossec, munin



Categories

/ (66)
    code/ (1)
    feed/ (1)
    friends/ (1)
    ossim/ (41)
        installer/ (3)
        plugins/ (2)
        tuning/ (3)
        tutorials/ (8)
    personal/ (20)
        campus/ (2)
        opinion/ (1)
        travel/ (1)
    rants/ (1)



Dominique Karg
(feel free to get in touch)
  • Mail (gpg key)
  • Linkedin
  • Twitter
  • Forums

Friend's blogs:
  • /blog/jaime
  • /blog/juanma
  • /blog/santiago






Certified Application Security Specialist




RSS




< February 2009 >
MoTuWeThFrSaSu
       1
2 3 4 5 6 7 8
9101112131415
16171819202122
232425262728 




Archives

2010-Apr
2010-Mar
2010-Feb
2009-Dec
2009-Sep
2009-Aug
2009-Jul
2009-Jun
2009-May
2009-Apr
2009-Mar
2009-Feb
2009-Jan
2008-Dec
2008-Oct
2008-Aug
2008-Jul
2008-May
2008-Mar
2008-Feb
2008-Jan
2007-Dec
2007-Nov




Tags

installer ossim tutorial untagged




Made with PyBlosxom