<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.1.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>OSSEC Home</title>
	<link>http://www.ossec.net/main</link>
	<description>OSSEC's Home</description>
	<pubDate>Wed, 25 Aug 2010 18:08:31 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.1.3</generator>
	<language>en</language>
			<item>
		<title>SecureCloud beta - Invitation to the OSSEC community</title>
		<link>http://www.ossec.net/main/securecloud-beta-invitation-to-the-ossec-community</link>
		<comments>http://www.ossec.net/main/securecloud-beta-invitation-to-the-ossec-community#comments</comments>
		<pubDate>Wed, 25 Aug 2010 18:07:17 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.ossec.net/main/securecloud-beta-invitation-to-the-ossec-community</guid>
		<description><![CDATA[Cloud adoption continues to grow at a fast pace with an annual compound growth rate of 28 percent. To secure applications in the cloud; security measures need to follow the applications no matter where they are in the cloud. Tools like OSSEC provide excellent protection for the host; but what about the data? 
Trend Micro [...]]]></description>
			<content:encoded><![CDATA[<p>Cloud adoption continues to grow at a fast pace with an annual compound growth rate of 28 percent. To secure applications in the cloud; security measures need to follow the applications no matter where they are in the cloud. Tools like OSSEC provide excellent protection for the host; but what about the data? </p>
<p><a href="https://www.trendbeta.com/index.php?get=357&#038;content=559">Trend Micro SecureCloud</a> compliments OSSEC in securing the data in the cloud while checking if OSSEC is being used on the host in the cloud. We would like to invite the OSSEC community that is using cloud services to the SecureCloud beta. </p>
<p>SecureCloud provides the following features: </p>
<ul>
<li>	Access control.</li>
<li>	Security information and event logging for the cloud.
</li>
<li>	Control over own security regardless of hosted provider security controls.
</li>
<li>	Protection from unauthorized access to data.
</li>
<li>	Privacy of data.
</li>
<li>	Data portability.
</li>
<li>	Adherence to enterprise policy controls.
</li>
</ul>
<p><a href="https://www.trendbeta.com/index.php?get=357&#038;content=559">Sign up today for the beta!</a></p>
<p>www.trendbeta.com</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ossec.net/main/securecloud-beta-invitation-to-the-ossec-community/feed/</wfw:commentRss>
		</item>
		<item>
		<title>OSSEC v2.4 released</title>
		<link>http://www.ossec.net/main/ossec-v24-released</link>
		<comments>http://www.ossec.net/main/ossec-v24-released#comments</comments>
		<pubDate>Thu, 01 Apr 2010 17:50:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.ossec.net/main/ossec-v24-released</guid>
		<description><![CDATA[The OSSEC team is very happy to announce the general availability of OSSEC version 2.4. 
What is new? We have lots of new features and bug fixes, but these are the main changes:

Added daily email summaries/reports. (more info)
Added option to alert when a log or command output changes - check_diff. (more info)
Added rules to ignore [...]]]></description>
			<content:encoded><![CDATA[<p>The OSSEC team is very happy to announce the general availability of OSSEC version <a href="http://www.ossec.net/main/downloads/">2.4</a>. </p>
<p>What is new? We have lots of new features and bug fixes, but these are the main changes:</p>
<ol>
<li>Added daily email summaries/reports. (<a href="http://www.ossec.net/dcid/?p=197">more info</a>)</li>
<li>Added option to alert when a log or command output changes - check_diff. (<a href="http://www.ossec.net/dcid/?p=198">more info</a>)</li>
<li>Added rules to ignore crawlers causing 404s (MSN, Google, Yahoo, etc).</li>
<li>Improved ossec-logtest to be used for the forensic analysis of log files  (<a href="http://www.ossec.net/dcid/?p=192">more info</a>)</li>
<li>Added support for Microsoft Security Essentials logs.</li>
</ol>
<p>And a few important bug fixes:</p>
<ul>
<li>Fixed a memory leak on the Windows agent that was not properly closing the sockets. It would cause a port exhaustion if the manager becames unavailable<br />
for a long period of time.</li>
<li>Fixed performance issue when the FTS queue was too large.</li>
</ul>
<p>Check out our <a href="http://www.ossec.net/announcements/v2.4-2010-04-01.txt">v2.4 changelog</a> for the complete list of new features and bugs fixed.</p>
<p>Download the new version from <a href="http://www.ossec.net/main/downloads">http://www.ossec.net/main/downloads</a></p>
<p><em>*Special thanks to our contributors Jeremy Rossi, Stephen Kreusch, Scott R. Shinn, Paul Southerington, Dan Parriott and Michael Starks and our beta testers Dan Parriott, Cristian Paul, Tobias Lott and David Dede</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ossec.net/main/ossec-v24-released/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Community Updates</title>
		<link>http://www.ossec.net/main/community-updates</link>
		<comments>http://www.ossec.net/main/community-updates#comments</comments>
		<pubDate>Mon, 15 Feb 2010 13:24:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.ossec.net/main/community-updates</guid>
		<description><![CDATA[The OSSEC community is on fire lately! We are very happy to see everyone talking and presenting about OSSEC. Those are some of the newest updates from our community:
Wim Remes spoke about OSSEC at the Fosdem conference. The video of his presentation is on youtube:





&#160;
Iñaki Rodríguez fromvirtualminds.es did a webmeeting about OSSEC in spanish. Slides [...]]]></description>
			<content:encoded><![CDATA[<p>The OSSEC community is on fire lately! We are very happy to see everyone talking and presenting about OSSEC. Those are some of the newest updates from our community:</p>
<p><strong><a href="http://blog.remes-it.be/">Wim Remes</a> spoke about OSSEC at the <a href="http://fosdem.org/2010/">Fosdem</a> conference. The video of his presentation is on youtube:</strong></p>
<object width="460" height="300">
<param name="movie" value="http://www.youtube.com/v/lUMs1uqwRX0&#038;hl=en_US&#038;fs=1&#038;"></param>
<param name="allowFullScreen" value="true"></param>
<param name="allowscriptaccess" value="always"></param>
<p><embed src="http://www.youtube.com/v/lUMs1uqwRX0&#038;hl=en_US&#038;fs=1&#038;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="460" height="300"></embed></object>
<p>&nbsp;<br />
<strong>Iñaki Rodríguez from<a href="http://www.virtualminds.es">virtualminds.es</a> did a webmeeting about OSSEC in spanish. Slides in PDF: </strong><br />
<a href="http://www.virtualminds.es/uploads/charlas/ossec-slides.pdf">http://www.virtualminds.es/uploads/charlas/ossec-slides.pdf</a></p>
<p>&nbsp;<br />
<strong>Wim Remes (yes, he again), wrote about OSSEC for the [IN]SECURE Magazine (2010 February edition):</strong><br />
<a href="http://www.net-security.org/insecuremag.php">http://www.net-security.org/insecuremag.php</a></p>
<p>&nbsp;<br />
<strong>Michael Starks from <a href="http://www.immutablesecurity.com/">immutablesecurity.com</a> posted a few interesting blog posts about OSSEC:</strong><br />
<a href="http://www.immutablesecurity.com/index.php/2010/01/29/using-ossec-for-encrypted-log-transport/">Using OSSEC for Encrypted Log Transport</a><br />
<a href="http://www.immutablesecurity.com/index.php/2010/01/13/detecting-sensitive-info-with-ossec/">Detecting Sensitive Info with OSSEC</a></p>
<p>Have you wrote something about OSSEC? Please, let us know and we will add in here.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ossec.net/main/community-updates/feed/</wfw:commentRss>
		</item>
		<item>
		<title>OSSEC v2.3 released</title>
		<link>http://www.ossec.net/main/ossec-v23-released</link>
		<comments>http://www.ossec.net/main/ossec-v23-released#comments</comments>
		<pubDate>Mon, 07 Dec 2009 14:12:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.ossec.net/main/ossec-v23-released</guid>
		<description><![CDATA[We are very happy to announce that general availability of OSSEC version 2.3 (just in time for the holidays).
What is new?

Log analysis rules for the Nginx web server
Log analysis rules for Suhosin (Hardened PHP)
Support for real time file integrity monitoring on Windows systems
Support for monitoring the output of commands (process monitoring)
And a lot more&#8230;

Check out [...]]]></description>
			<content:encoded><![CDATA[<p>We are very happy to announce that general availability of OSSEC version <a href="http://www.ossec.net/main/downloads/">2.3</a> (just in time for the holidays).</p>
<p><strong>What is new?</strong></p>
<ol>
<li>Log analysis rules for the Nginx web server</li>
<li>Log analysis rules for Suhosin (Hardened PHP)</li>
<li>Support for <a href="http://www.ossec.net/main/manual/manual-syscheck/realtime-file-integrity-monitoring/">real time file integrity monitoring</a> on Windows systems</li>
<li>Support for monitoring the <a href="http://www.ossec.net/main/manual/manual-process-monitoring/">output of commands</a> (process monitoring)</li>
<li>And a lot more&#8230;</li>
</ol>
<p>Check out our <a href="http://www.ossec.net/announcements/v2.3-2009-12-07.txt">v2.3 changelog</a> of the complete list of new features and bugs fixed.</p>
<p>Download the new version from <a href="http://www.ossec.net/main/downloads">http://www.ossec.net/main/downloads</a></p>
<p><em>*Special thanks to our contributors Jeremy Rossi, Fabio Paracchini and Michael Starks and our beta testers Dan Parriott, Michael Starks, Timo Vehvilainen and Jeremy Rossi.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ossec.net/main/ossec-v23-released/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Week of OSSEC</title>
		<link>http://www.ossec.net/main/week-of-ossec</link>
		<comments>http://www.ossec.net/main/week-of-ossec#comments</comments>
		<pubDate>Sat, 31 Oct 2009 12:47:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.ossec.net/main/week-of-ossec</guid>
		<description><![CDATA[Michael Starks from Immutable Security finished today his series of articles about OSSEC called &#8220;Week of OSSEC&#8220;. It was meant to coincide with his speak on OSSEC at the Rochester Security Summit.
From his blog:

As a service to the community and to coincide with my speaking on OSSEC at the Rochester Security Summit, every day during [...]]]></description>
			<content:encoded><![CDATA[<p>Michael Starks from <a href="http://www.immutablesecurity.com/">Immutable Security</a> finished today his series of articles about OSSEC called &#8220;<em>Week of OSSEC</em>&#8220;. It was meant to coincide with his speak on OSSEC at the Rochester Security Summit.</p>
<p>From his blog:</p>
<blockquote><p>
As a service to the community and to coincide with my speaking on OSSEC at the Rochester Security Summit, every day during the week of October 25 through October 31, I’ll be posting a new tip on OSSEC based on my years of first-hand experience. These are the tips that make the software more usable for me and hopefully, it will for you, too. Have a tip that has helped you? Be sure to post it in the comments.
</p></blockquote>
<p>Links to the articles:</p>
<ul>
<li><a href="http://www.immutablesecurity.com/index.php/2009/10/25/week-of-ossec-day-1-detecting-world-writable-files/">Day 1: Detecting World-Writable Files</a></li>
<li><a href="http://www.immutablesecurity.com/index.php/2009/10/26/week-of-ossec-day-2-detecting-new-files/">Day 2: Detecting New Files</a></li>
<li><a href="http://www.immutablesecurity.com/index.php/2009/10/27/week-of-ossec-day-3-use-variables/">Day 3: Using Variables</a></li>
<li><a href="http://www.immutablesecurity.com/index.php/2009/10/28/week-of-ossec-day-4-using-groups/">Day 4: Using Groups</a></li>
<li><a href="http://www.immutablesecurity.com/index.php/2009/10/29/week-of-ossec-day-5-reusing-rule-ids/">Day 5: Reusing Rule IDs</a></li>
<li><a href="http://www.immutablesecurity.com/index.php/2009/10/30/week-of-ossec-day-6-developing-a-tuning-strategy/">Day 6: Developing a Tuning Strategy</a></li>
<li><a href="http://www.immutablesecurity.com/index.php/2009/10/31/week-of-ossec-day-7-developing-a-workflow/">Day 7: Developing a Workflow</a></li>
</ul>
<p>Be sure to check it out to learn more about OSSEC. Thanks Michael for sharing your experience with us.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ossec.net/main/week-of-ossec/feed/</wfw:commentRss>
		</item>
		<item>
		<title>OSSEC v2.2 released</title>
		<link>http://www.ossec.net/main/ossec-v22-released</link>
		<comments>http://www.ossec.net/main/ossec-v22-released#comments</comments>
		<pubDate>Tue, 08 Sep 2009 11:56:29 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.ossec.net/main/ossec-v22-released</guid>
		<description><![CDATA[We are pleased to announce the general availability of OSSEC version 2.2.
This is a stability release, with heavy focus on bug fixes, code cleanup and a few new features. The most notable changes are:

Trend OSCE (Office scan) support - We added rules to properly monitor and analyze Trend logs
Wordpress Monitoring - Wordpress is a popular [...]]]></description>
			<content:encoded><![CDATA[<p>We are pleased to announce the general availability of OSSEC <a href="/main/downloads/">version 2.2</a>.<br />
This is a stability release, with heavy focus on bug fixes, code cleanup and a few new features. The most notable changes are:</p>
<ul>
<li><strong>Trend OSCE (Office scan)</strong> support - We added rules to properly monitor and analyze Trend logs</li>
<li><strong>Wordpress Monitoring</strong> - <a href="http://www.wordpress.org">Wordpress</a> is a popular blogging platform with very little logging by default. We create a <a href="http://www.ossec.net/wpsyslog2">plugin</a> to extend its logging capabilities and created rules on OSSEC to monitor it.</li>
<li><strong>More Logging support</strong> - We added support for vpopmail, roundcube, Netscreen IDS and a few more log formats.</li>
</ul>
<p>And much more&#8230; Check out the <a href="/announcements/v2.2-2009-09-08.txt">changelog</a> to see all changes and contributors.</p>
<p>Download it from: <a href="http://www.ossec.net/main/downloads">http://www.ossec.net/main/downloads</a> .</p>
<p><em>Special thanks to Aleksander Podsiad, Michael Starks and Dan Parriott for the contributions to this release.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ossec.net/main/ossec-v22-released/feed/</wfw:commentRss>
		</item>
		<item>
		<title>OSSEC v2.1 released</title>
		<link>http://www.ossec.net/main/ossec-v21-released</link>
		<comments>http://www.ossec.net/main/ossec-v21-released#comments</comments>
		<pubDate>Tue, 30 Jun 2009 12:14:03 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.ossec.net/main/ossec-v21-released</guid>
		<description><![CDATA[We are pleased to announce the general availability of OSSEC version 2.1.
This new version is the first one with support for centralized configurations and realtime integrity monitoring on Linux. It also includes many other features and bug fixes:

Centralized configuration - The agent.conf file was introduced to allow granular configuration of the agents directly on the [...]]]></description>
			<content:encoded><![CDATA[<p>We are pleased to announce the general availability of OSSEC <a href="/main/downloads/">version 2.1</a>.<br />
This new version is the first one with support for centralized configurations and realtime integrity monitoring on Linux. It also includes many other features and bug fixes:</p>
<ul>
<li><strong>Centralized configuration</strong> - The <em>agent.conf</em> file was introduced to allow granular configuration of the agents directly on the manager side. </li>
<li><strong>Remote agent restart</strong> - Functionality was added to restart the agents remotely using the <em>agent_control</em> tool.</li>
<li><strong>Real time integrity checking</strong> - Real time integrity checking was added to Linux systems.</li>
<li><strong>New Log Rules Support</strong> - We added support for Windows DHCP logs and fixed/improved many of the other rules for different messages.</li>
</ul>
<p>And much more&#8230; Check the <a href="/announcements/v2.1-2009-06-30.txt">changelog</a> to see all changes and contributors.</p>
<p>Download it from: <a href="http://www.ossec.net/main/downloads">http://www.ossec.net/main/downloads</a> .</p>
<p><em>Special thanks to Chris Bailes, Matt Goldsberry, phishphreek, Michael Starks, Danny Fullerton, Slava Semushin and Peter Wolanin for helping with this release.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ossec.net/main/ossec-v21-released/feed/</wfw:commentRss>
		</item>
		<item>
		<title>I (HEART) OSSEC</title>
		<link>http://www.ossec.net/main/i-heart-ossec</link>
		<comments>http://www.ossec.net/main/i-heart-ossec#comments</comments>
		<pubDate>Fri, 19 Jun 2009 13:07:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.ossec.net/main/i-heart-ossec</guid>
		<description><![CDATA[This is a guest article by Justin Foster of  DevelopingSecurity.com


In the open source world some projects have taken on beloved status by their loyal user base. OSSEC is one of them, and for good reason.
For those of you unfamiliar, OSSEC (pronounced Oh-Sec) is an Open Source Host-based Intrusion Detection System. It performs log analysis, [...]]]></description>
			<content:encoded><![CDATA[<p><em>This is a guest article by <strong>Justin Foster</strong> of <a target="_blank" href="http://developingsecurity.com"> DevelopingSecurity.com</a></em>
</p>
<p><img alt="Iheartossec" src="http://www.developingsecurity.com/.a/6a011279135bcf28a40115702e2a59970c-250wi" style="margin: 0px 0px 5px 5px; width: 220px;" align="right" /></p>
<p>In the open source world some projects have taken on beloved status by their loyal user base. OSSEC is one of them, and for good reason.</p>
<p>For those of you unfamiliar, <a href="http://www.ossec.net/main/" target="_blank">OSSEC</a> (pronounced Oh-Sec) is an Open Source Host-based Intrusion Detection System. It performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response. </p>
<p>Over a year and a half ago I was tasked to review OSSEC as a potential acquisition for Third Brigade. I was of course, sufficiently impressed with OSSEC&#8217;s capabilities, but I was surprised at the level of respect it had developed in the community. I was curious as to why OSSEC had such a solid reputation.</p>
<p>Recently I have gotten to know the man who literally wrote <a href="http://www.amazon.com/OSSEC-Host-Based-Intrusion-Detection-Guide/dp/159749240X/ref=sr_1_1?ie=UTF8&amp;s=books&amp;qid=1245324171&amp;sr=8-1"target="_blank">the book</a> on OSSEC, <a href="http://www.andrewhay.ca/" target="_blank">Andrew Hay</a>. Andrew is a well respected figure in the security community and has authored several security texts in addition to his <a href="http://www.andrewhay.ca/" target="_blank">daily blogs</a>.  He thinks, &#8220;The key drivers to the product are 1) the cost, 2) the ease to deploy, and 3) the community wrapped around it&#8221;. </p>
<p>It&#8217;s true, like other popular open source security projects (like <a href="http://www.snort.org/" target="_blank">Snort</a>), OSSEC has a strong community. Its members get involved by contributing to <a href="http://www.ossec.net/wiki/index.php/OSSEC" target="_blank">the wiki</a>, communicating on the <a href="http://groups.google.com/group/ossec-list" target="_blank">mailing-list</a>, and discussing OSSEC on <a href="http://search.twitter.com/search?q=ossec" target="_blank">Twitter</a> (where Andrew <a href="https://twitter.com/andrewsmhay/status/2121136131" target="_blank">tries</a> to get anyone who mentions OSSEC to buy his book). </p>
<p>I asked Wim Remes, who recently posted <a href="http://blog.remes-it.be/?p=231" target="_blank">OSSEC in a Nutshell</a> on his blog, and he said OSSEC succeeds because &#8220;it&#8217;s cross-platform, it&#8217;s free (the software is &#8230; not the implementation), it&#8217;s giga-flexible, it does what it promises to do&#8221;. &#8216;Giga-flexible&#8217;, I like that word. I&#8217;ll have to trademark it before Wim does! :) These sentiments are shared by many who have given OSSEC a try. </p>
<p>The acclaim for OSSEC extends to the press as well. In &#8216;07 LinuxWorld named OSSEC the <a href="http://www.linuxworld.com/news/2007/031207-top-5-security.html" target="_blank">#1 Open Source Security Tool</a>. They explained, &#8220;The OSSEC HIDS project has been gaining widespread use and is quickly being deployed within organizations around the world as a method of protecting systems at the host level after attacks have made it past network defenses&#8221;. Recently <a href="http://www.zdnetasia.com/techguide/opensource/0,39044899,62052219,00.htm" target="_blank">ZDnet</a> also covered OSSEC saying, &#8220;Danen singles out OSSEC as a solid, cross-platform tool for intrusion detection&#8221;. The OSSEC website has a large list of <a href="http://www.ossec.net/main/awards/" target="_blank">awards and reviews</a>.</p>
<p>Clearly OSSEC is a solid, cross-platform piece of software at an unbeatable price, but it takes more than that to build a loyal following.</p>
<p>I think the <strong>real reason</strong> for OSSEC&#8217;s success is its creator <a href="http://www.linkedin.com/pub/daniel-cid/0/324/465" target="_blank">Daniel Cid</a>, and his roots. </p>
<p>The seeds for OSSEC were planted back when Daniel was a security engineer. He found that in his job he lacked information about the hosts he was protecting and started writing scripts that would give him a better picture of the state of the network. Because Daniel came from an operations background rather than a pure development background, he writes software to solve real problems he actually faced. </p>
<p>Still, it takes more than a problem solver. When I first met Daniel he was working a full time job, OSSEC was a side project. It was clear that he really cared about the project and supporting OSSEC users event if it meant many grueling nights and weekends. Users would send him new log samples to deal with and on his own time Daniel would dissect the logs, create decoders and rank the security relevant events. Daniel answers every email, deals with every bug, and considers every enhancement request. It doesn&#8217;t hurt that he&#8217;s a genuinely nice guy too! </p>
<p>So OSSEC&#8217;s real popularity comes from the fact that it does what users want it to do. That sounds like an incredibly obvious attribute which all software should strive for, but it&#8217;s much more attainable when it&#8217;s developed by someone who has been there and listens to feedback. This is something to keep in mind for all of the commercial software developers out there, <a href="http://www.developingsecurity.com" target="_blank">like myself</a>. </p>
<p><strong>We need to walk a mile in the shoes of the end-user and listen when they have feedback.</strong></p>
<p>Because of the positive experiences using OSSEC it continues to grow in popularity. Largely through word of mouth, OSSEC has grown to over 10,000 downloads a month! </p>
<p>Have you tried OSSEC? Maybe you&#8217;ll find that you&#8217;ll (HEART) OSSEC too.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ossec.net/main/i-heart-ossec/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Splunk + OSSEC Integration</title>
		<link>http://www.ossec.net/main/splunk-ossec-integration</link>
		<comments>http://www.ossec.net/main/splunk-ossec-integration#comments</comments>
		<pubDate>Tue, 02 Jun 2009 18:15:42 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.ossec.net/main/splunk-ossec-integration</guid>
		<description><![CDATA[This is a guest article by Dale Neufeld - canuck.eh at gmail.com
The status of the next version of the OSSEC web interface is one of the more commonly asked questions on the mailing list and is currently #2 on the community requested feature list (http://ossec.uservoice.com).
While web interfaces are nice to have, many of us suffer [...]]]></description>
			<content:encoded><![CDATA[<p><em>This is a guest article by <strong>Dale Neufeld</strong> - canuck.eh at gmail.com</em></p>
<p>The status of the next version of the OSSEC web interface is one of the more commonly asked questions on the mailing list and is currently #2 on the community requested feature list (<a href="http://ossec.uservoice.com">http://ossec.uservoice.com</a>).</p>
<p>While web interfaces are nice to have, many of us suffer from information island overload by having dedicated web interfaces for each application.  This is why I was stoked when the <em>syslog ouput</em> feature was announced last summer (<a href="http://www.ossec.net/dcid/?p=139">http://www.ossec.net/dcid/?p=139</a>) and officially added in <a href="http://www.ossec.net/announcements/1.6-2008-09-02.txt">version 1.6</a>.  Now I can incorporate OSSEC alerts into my SIM/SIEM or log management tool of choice, which not only eliminates the need for a dedicated OSSEC web interface but also allows for simplified incident analysis through aggregation and correlation.</p>
<p>In my environment, we chose <a href="http://www.splunk.com">Splunk</a> based on its quick search and endless customization.  Getting <strong>OSSEC</strong> alerts into Splunk is a breeze.  Just grab the free license version of Splunk, install the Splunk for OSSEC app, and point the OSSEC syslog output to your Splunk server.  BAM! Instant<em> wui 0.4</em>.</p>
<p>The Splunk-for-OSSEC application is a community project that was started by myself and Elazar Broad.  The initial goal of this application was to provide the same set of reports that can be obtained through <em>ossec-reportd</em>.  From there we&#8217;ve also added several other useful features:</p>
<ol>
<li>Top rules last 24 hrs</li>
<li>Top source IP last 24 hrs</li>
<li>Top user last 24 hrs</li>
<li>Bruteforce top source IP last 24 hrs</li>
<li>OSSEC rules for last hour</li>
<li>OSSEC alert levels for last 24 hrs</li>
<li>IP Geolocation lookups</li>
<li>whois lookups</li>
<li>rDNS lookups</li>
<li>web attack and bruteforce tags.</li>
</ol>
<p><strong>Screenshots:</strong></p>
<p><a href='http://www.ossec.net/main/wp-content/uploads/2009/06/ossec-splunk-ss-4.png' title='Splunk 4'><img src='http://www.ossec.net/main/wp-content/uploads/2009/06/ossec-splunk-ss-4.thumbnail.png' alt='Splunk 4' /></a></p>
<p><a href='http://www.ossec.net/main/wp-content/uploads/2009/06/ossec-splunk-ss-2.png' title='splunk 2'><img src='http://www.ossec.net/main/wp-content/uploads/2009/06/ossec-splunk-ss-2.thumbnail.png' alt='splunk 2' /></a></p>
<p><a href='http://www.ossec.net/main/wp-content/uploads/2009/06/ossec-splunk-ss-3.png' title='Splunk 3'><img src='http://www.ossec.net/main/wp-content/uploads/2009/06/ossec-splunk-ss-3.thumbnail.png' alt='Splunk 3' /></a></p>
<p><a href='http://www.ossec.net/main/wp-content/uploads/2009/06/ossec-splunk-ss-1.png' title='Splunk 1'><img src='http://www.ossec.net/main/wp-content/uploads/2009/06/ossec-splunk-ss-1.thumbnail.png' alt='Splunk 1' /></a></p>
<p><strong>OSSEC and Splunk configuration instructions</strong></p>
<p>More details at the <a href="http://www.ossec.net/wiki/index.php/OSSEC_%26_Splunk">ossec wiki</a>.</p>
<ol>
<li>Inside ossec.conf add a <em>syslog_output</em> block specifying your Splunk system IP address and the port it is listening on:<br />
<blockquote><p>
 &lt;syslog_output&gt;<br />
   &lt;server&gt;172.10.2.3&lt;/server&gt;<br />
   &lt;port&gt;10002&lt;/port&gt;<br />
 &lt;/syslog_output&gt;</p></blockquote>
</li>
<li>Now you need to enable the syslog_output module and restart OSSEC:<br />
<blockquote><p>
 #/var/ossec/bin/ossec-control enable client-syslog<br />
 #/var/ossec/bin/ossec-control restart
</p></blockquote>
</li>
<li>On the Splunk side, add this stanza to inputs.conf:<br />
<blockquote><p> $SPLUNK_HOME/etc/system/local/inputs.conf</p>
<p> [udp://172.10.2.4:10002] #IP address of OSSEC server<br />
 disabled = false<br />
 sourcetype = ossec</p></blockquote>
<p>By setting the sourcetype as OSSEC you&#8217;re ready to take advantage of the Splunk for OSSEC app which can be found here: <a href="http://www.splunkbase.com/apps/All/Security/app:Splunk+for+OSSEC">http://www.splunkbase.com/apps/All/Security/app:Splunk+for+OSSEC</a>.</p>
</li>
<li>Make sure you update any local or network firewalls that this communication is traversing and then restart Splunk.<br />
<blockquote><p># $SPLUNK_HOME/bin/splunk restart</p></blockquote>
</li>
</ol>
<p><strong>Splunk:</strong><br />
<a href="http://www.splunk.com/download">http://www.splunk.com/download</a></p>
<p><strong>Splunk-for-OSSEC:</strong><br />
<a href="http://www.splunkbase.com/apps/All/Security/app:Splunk+for+OSSEC#">http://www.splunkbase.com/apps/All/Security/app:Splunk+for+OSSEC#</a></p>
<p>Feedback and feature requests are much appreciated!</p>
<p>If you&#8217;ve used the syslog ouput to send alerts to another SIM/SIEM or log management tool, we would love to hear from you so we can add configuration details to the wiki.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ossec.net/main/splunk-ossec-integration/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Trend Micro to Acquire Third Brigade</title>
		<link>http://www.ossec.net/main/trend-micro-to-acquire-third-brigade</link>
		<comments>http://www.ossec.net/main/trend-micro-to-acquire-third-brigade#comments</comments>
		<pubDate>Wed, 29 Apr 2009 12:45:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.ossec.net/main/trend-micro-to-acquire-third-brigade</guid>
		<description><![CDATA[

What was announced?


On April 29, 2009 Trend Micro announced a definitive agreement to acquire the business of Third Brigade, a privately-held security and compliance software company headquartered in Ottawa, Canada that owns the OSSEC project. The acquisition is subject to customary approvals and is expected to close in the 2nd quarter of 2009.  
&#160;


Who [...]]]></description>
			<content:encoded><![CDATA[<ol>
<li>
<p style="margin-bottom: 0cm"><font color="#00467f"><strong>What was announced?</strong></font></p>
</li>
</ol>
<p style="margin-left: 1.27cm; margin-bottom: 0cm"><font color="#000000">On April 29, 2009 Trend Micro announced a definitive agreement to acquire the business of Third Brigade, a privately-held security and compliance software company headquartered in Ottawa, Canada that owns the OSSEC project. The acquisition is subject to customary approvals and is expected to close in the 2nd quarter of 2009.  </font></p>
<p style="margin-left: 1.27cm; margin-bottom: 0cm">&nbsp;</p>
<ol start="2">
<li>
<p style="margin-bottom: 0cm"><font color="#00467f"><strong>Who is Trend Micro?</strong></font></p>
</li>
</ol>
<p style="margin-left: 1.27cm; margin-bottom: 0cm"><font color="#000000">Trend Micro Incorporated is a pioneer in secure content and threat management. Founded in 1988, Trend Micro provides individuals and organizations of all sizes with award-winning security software, hardware and services. With headquarters in Tokyo and operations in more than 30 countries, Trend Micro solutions are sold through corporate and value-added resellers and service providers worldwide. For additional information and evaluation copies of Trend Micro products and services, visit our Web site at </font><font color="#0000ff"><u><a href="http://www.trendmicro.com/">www.trendmicro.com</a></p>
<p></u></font><font color="#000000">.</font></p>
<p style="margin-left: 1.27cm; margin-bottom: 0cm"><font color="#000000"> </font></p>
<ol start="3">
<li>
<p style="margin-bottom: 0cm"><font color="#00467f"><strong>Will 	OSSEC continue to be an open source project?</strong></font></p>
</li>
</ol>
<p style="margin-left: 1.27cm; margin-bottom: 0cm">Yes.  Trend Micro is committed to maintaining OSSEC as an open source project.</p>
<p style="margin-left: 1.27cm; margin-bottom: 0cm">&nbsp;</p>
<ol start="4">
<li>
<p style="margin-bottom: 0cm"><font color="#00467f"><strong>What 	impact will this acquisition have on an OSSEC user?</strong></font></p>
</li>
</ol>
<p style="margin-left: 1.27cm; margin-bottom: 0cm">We don’t anticipate there will be any impact on OSSEC users from this acquisition.  Like Third Brigade, Trend will help create broader awareness and further ensure the success of this thriving open source community through ongoing dedicated resources and extended support necessary for larger enterprise deployments.</p>
<p style="margin-left: 1.27cm; margin-bottom: 0cm">&nbsp;</p>
<ol start="5">
<li>
<p style="margin-bottom: 0cm"><font color="#00467f"><strong>Will 	Trend Micro continue to offer commercial support for OSSEC? </strong></font></p>
</li>
</ol>
<p style="margin-left: 1.27cm; margin-bottom: 0cm">Yes, technical support will continue to be offered via the same two channels:</p>
<ul>
<li>
<p style="margin-bottom: 0cm">Telephone: 8:00 am and 8:00 pm 	(Eastern Time), Monday to Friday.</p>
</li>
<li>
<p style="margin-bottom: 0cm">Email: Third Brigade provides an 	initial response to a customer support request within one business 	day.</p>
</li>
</ul>
<p style="margin-left: 1.27cm; margin-bottom: 0cm">&nbsp;</p>
<ol start="6">
<li>
<p style="margin-bottom: 0cm"><font color="#00467f"><strong>How does an OSSEC user buy support? </strong></font></p>
</li>
</ol>
<p style="margin-left: 1.27cm; margin-bottom: 0cm">OSSEC users that would like to purchase support should continue to contact Third Brigade sales, at 1.866.684.7332 or <font color="#0000ff"><u><a href="mailto:ossec.purchase@thirdbrigade.com">ossec.purchase@thirdbrigade.com</a></u></font>.</p>
<p style="margin-left: 1.27cm; margin-bottom: 0cm">&nbsp;</p>
<ol start="7">
<li>
<p style="margin-bottom: 0cm"><font color="#00467f"><strong>How are 	OSSEC support requests handled? </strong></font></p>
</li>
</ol>
<p style="margin-left: 1.27cm; margin-bottom: 0cm">Requests for OSSEC support should continue to be directed to Third Brigade Support at 1.866.343.8077, and <font color="#0000ff"><u><a href="mailto:ossec.support@thirdbrigade.com">ossec.support@thirdbrigade.com</a></u></font></p>
<p></p>
<p>Thanks!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ossec.net/main/trend-micro-to-acquire-third-brigade/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
