I’ve just finished committing the first alpha release of ClearCutter to the Alienvault-Garage repository on GoogleCode. It’s a tool born of necessity, for anyone whose spent a good amount of time on those ‘SIEM pre-processing’ tasks, neck-deep in sed, grep,awk, uniq.
Clearcutter (because it ‘clears a forest of logs’) is my work-in-progress combination tool for all those log pre-analysis tasks we here at Alienvault find ourselves doing repetitively. We figure if it’s useful to us, it will be just as useful to other people out there looking to add new device types into OSSIM and find the log entries they need to build effective correlation rules:
Here’s a short planned feature list
- Find Individual Log messages in a log file - ever tried to find all the unique message types in a log sample? this will do it for you.
- Make constructing OSSIM collector plugins easier - assistance in writing regexp’s for OSSIM plugin SID entries
- Find Sequences of Logs in a log file (complete behavioral actions) - need to find all the log messages that indicate a complete user session?
- Produce Sequence configs and process logs into sequence summaries
- Test OSSIM collector plugins against log samples - validate that you have a valid plugin config and show what gets parsed by what SID
- Profile individual regex’s/SID’s against sample logs to see which consume most CPU time - solve those performance mysteries.