套件:sagan(1.2.0-1.2)
Real-time System & Event Log Monitoring System
Sagan is a multi-threaded, real time system- and event-log monitoring system, but with a twist. Sagan uses a “Snort” like rule set for detecting malicious events happening on your network and/or computer systems. If Sagan detects a potentially bad event, that event can be stored to a Snort database (MySQL/PostgreSQL), send it to a SIEM tool like Prelude, or send an email. Sagan is meant to be used in a ‘centralized’ logging environment, but will work fine as part of a standalone Host IDS system for workstations.
其他與 sagan 有關的套件
|
|
|
|
-
- dep: adduser
- 新增、移除使用者與群組
-
- dep: libc6 (>= 2.28)
- GNU C 函式庫:共用函式庫
同時作為一個虛擬套件由這些套件填實: libc6-udeb
-
- dep: libfastjson4 (>= 0.99.3)
- fast json library for C
-
- dep: liblognorm5 (>= 0.3.0)
- log normalizing library
-
- dep: libpcre3
- Old Perl 5 Compatible Regular Expression Library - runtime files
-
- dep: libyaml-0-2
- Fast YAML 1.1 parser and emitter library
-
- dep: lsb-base (>= 3.0-6)
- Linux Standard Base init script functionality
-
- dep: sagan-rules
- Real-time System & Event Log Monitoring System [rules]