3 ms·
I have heard good words about OSSEC but never tried it because of it's perception being: - heavyweight; - not actively developed. Are my perceptions right? I
by daemon13 14y ago
I have heard good words about OSSEC but never tried it because of it's perception being:
- heavyweight;
- not actively developed.
Are my perceptions right? If no, how would you recommend to start using it? Any good tutorials or other pointers?
- matwizzle 14y agoLast version dates from 2012-11-19, not the fastest of releases - but seems ok. Trend Micro is involved (and offers commercial support). It doesn't feel heavyweight to me. It does start a bunch of daemons for all of its processing and it has the client->server bit built right in. That may make it feel heavyweight, I guess. But, you don't have to use the client->server stuff if you don't want to. It'll still do all of its magic for you. Ossec will do a lot out of the box. So, I suggest installing it with the default ruleset and the active-response stuff turned off (the installer will ask you). Then dive into the rules and ossec.conf (knowledge of regex is required). Documentation @ http://www.ossec.net/doc/index.html http://www.ossec.net/doc/index.html
- druiid 14y agoOssec is actively developed. They just had a new release a few months ago. Realistically it doesn't get updated as much as it used to, but it still is actively developed. I think more than anything it is just kind of at a near end-state where there isn't a whole lot left to ADD other than some signature type updates, or nice-to-have features. It is a program that I HIGHLY recommend having and it is very simple to get up and running, even if you don't have packages of it for your OS version. Also you won't pass PCI-1 without a IDS like this.