devialog is a behavior/anomaly-based syslog intrusion detection system which detects unknown attacks via anomalies in syslog. It can generate signatures for ease of management, act upon anomalies in a predefined fashion or perform as a standard log parser
Be the first to post a text review of devialog. Rate and review a project by clicking thumbs up or thumbs down in the right column.
Major fix with handling of non-standard syslog messages. For example, a Cisco-based VPN will toss out messages in a format that looks quite dissimilar to 'Jan 1 01:01:01 machine process[pid]: message". devialog now understands and can parse more of the wild syslog messages out there. Signatures now have a reusable comments and line field. "comments" field simply means each signature can have comments attached to it which will not go away when new signatures are generated. Signatures now also have a "line" field. The line field is merely the exact syslog line in which the signature was created. This is useful for folks who are not regular expression gurus. Bug in devialogsig fixed that would not permit a user to read in the previously created signature file. Now the -r option should work for everyone.
Be the first person to add a text review.
Copyright © 2009 Geeknet, Inc. All rights reserved. Terms of Use
Thanks for your rating!
Would you also like to write a review?
Thanks for your review!
Get credit for your review by logging in via OpenID. Click your account provider: