[ 源代码: sagan ]
软件包:sagan(1.2.0-1)
Real-time System & Event Log Monitoring System
Sagan is a multi-threaded, real time system- and event-log monitoring system, but with a twist. Sagan uses a “Snort” like rule set for detecting malicious events happening on your network and/or computer systems. If Sagan detects a potentially bad event, that event can be stored to a Snort database (MySQL/PostgreSQL), send it to a SIEM tool like Prelude, or send an email. Sagan is meant to be used in a ‘centralized’ logging environment, but will work fine as part of a standalone Host IDS system for workstations.
其他与 sagan 有关的软件包
|
|
|
|
-
- dep: adduser
- 添加、删除用户和组
-
- dep: libc6 (>= 2.4)
- GNU C 语言运行库:共享库
同时作为一个虚包由这些包填实: libc6-udeb
-
- dep: libee0 (>= 0.3.0)
- Event expression library inspired by CEE
-
- dep: libestr0 (>= 0.1.0)
- 处理字符串的辅助函数(库文件)
-
- dep: libfastjson4 (>= 0.99.3)
- 用于 C 语言的快速 json 库
-
- dep: liblognorm5 (>= 0.3.0)
- 日志标准化库
-
- dep: libpcre3
- 与旧版 Perl 5 兼容的正则表达式库 - 运行文件
-
- dep: libyaml-0-2
- Fast YAML 1.1 parser and emitter library
-
- dep: lsb-base (>= 3.0-6)
- Linux 标准规范初始化脚本功能
-
- dep: sagan-rules
- Real-time System & Event Log Monitoring System [rules]