LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-30-2010, 12:34 PM   #1
scucci
Member
 
Registered: Sep 2009
Posts: 31

Rep: Reputation: 15
Linux SIEM (Logging/Correlating/Monitoring)


I'm going to start monitoring our Linux servers with a log management/correlation tool to take a proactive approach to the security of our systems. Right now I'm going to search for log events that include the following:

Failed user login “authentication failure”,“failed password”

User account change or deletion “password changed”,“new user”,“delete user”

Sudo actions “sudo:COMMAND=…” “FAILED su”

Service failure “failed” or “failure”

Can anyone else recomend any other commands or logs that would be good to correlate or be alerted on when a potential breach or suspicous activity is happening on the box? Logging cleared, permission changes on accounts or particular files or directories? What would you want to see while monioring your servers? Is anyone doing anything similar?
 
Old 09-30-2010, 02:29 PM   #2
OlRoy
Member
 
Registered: Dec 2002
Posts: 306

Rep: Reputation: 86
For log monitoring like that, it might be easier to use OSSEC rather than trying to reinvent the wheel, if that's what your doing.
 
Old 09-30-2010, 02:45 PM   #3
scucci
Member
 
Registered: Sep 2009
Posts: 31

Original Poster
Rep: Reputation: 15
I am using a correlation engine, but I'd like to have a few more custom rules that might not already be in it.

Any suggestions?
 
Old 09-30-2010, 02:51 PM   #4
OlRoy
Member
 
Registered: Dec 2002
Posts: 306

Rep: Reputation: 86
Quote:
Originally Posted by scucci View Post
I am using a correlation engine, but I'd like to have a few more custom rules that might not already be in it.

Any suggestions?
Check out this blog post from the log master himself, Anton Chuvakin. You may also find the rules from OSSEC helpful.
 
1 members found this post helpful.
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Bandwidth logging and monitoring on interface lpallard Linux - Networking 10 06-27-2010 09:32 PM
LXer: Power monitoring and logging with Apcupsd and Cacti LXer Syndicated Linux News 0 09-05-2008 01:00 AM
LXer: Using Mkfifo For Monitoring And Enhanced User Activity Logging LXer Syndicated Linux News 0 07-10-2008 06:20 PM
how to build a activities monitoring and logging system roamer_xk Programming 2 07-14-2005 05:49 PM
how to build a activities monitoring and logging system roamer_xk Linux - Security 1 07-14-2005 01:16 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:22 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration