![]() |
Collecting events with rsyslog Tue, 08 Sep 2009 This article tries to be a small how-to about OSSIM events collection using rsyslog. For example lets try to configure OSSIM to collect events from a Netscreen firewall. OSSIM agent
RsyslogThen it's time to go through rsyslogd configuration.
/etc/init.d/rsyslogd restart
At this point it should be listening at port 514 (the default one), you can check it with netstat command. So, once we configure our device to send logs to our OSSIM sensor, they should be collected and correlated. As you can see this how-to is quite simple, but I hope it can help you with your configurations or help me to remember it if needed. Regards. posted at: 10:55 | path: /ossim/configs | permanent link to this entry | 0 comments |
|
Categories
/ (4) Santiago Gonzalez (feel free to get in touch) Friend's blogs:
Archives Tags | |||||||||||||||||||||||||||||||||||||||||||||||||


