[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#609893: ITP: sagan -- Real-time System & Event Log Monitoring System



Package: wnpp
Severity: wishlist
Owner: Pierre Chifflier <pollux@debian.org>

* Package name    : sagan
  Version         : 0.7.1
  Upstream Author : Champ Clark III <champ@softwink.com>
* URL             : http://sagan.softwink.com/
* License         : GPLv2
  Programming Lang: C
  Description     : Real-time System & Event Log Monitoring System

Sagan is a multi-threaded, real time system- and event-log monitoring
system, but with a twist. Sagan uses a “Snort” like rule set for
detecting “bad things” happening on your network and/or computer
systems.
If Sagan detects a “bad thing” happening, that event can be stored to a
Snort database (MySQL/PostgreSQL) and Sagan will correlate the event
with your Snort Intrusion Detection/Intrusion Prevention system or send
it to a SIEM tool like Prelude.
Sagan is meant to be used in a ‘centralized’ logging environment, but
will work fine as part of a standalone Host IDS system for workstations.



Reply to: