LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-09-2018, 11:07 AM   #1
Quirinus
LQ Newbie
 
Registered: Feb 2018
Posts: 3

Rep: Reputation: Disabled
Tips for security monitoring Linux


Hello, people.
I'm looking for some article that have relative to "how to be guru in security monitoring".
For example, i'm using splunk + ossec + auditd, monitoring bash history,
I'm not monitoring network (so, any tips about it will be cool). How to example, monitoring linux firewall?

Maybe, any information that can help me detect bad hackers who want to get access to my PC (indicators of compromise).

For me it's shit monitoring and I'm junior in this issue, so any guides will be help me.

Thank you!
 
Old 02-09-2018, 11:24 AM   #2
BW-userx
LQ Guru
 
Registered: Sep 2013
Location: Somewhere in my head.
Distribution: Slackware (15 current), Slack15, Ubuntu studio, MX Linux, FreeBSD 13.1, WIn10
Posts: 10,342

Rep: Reputation: 2242Reputation: 2242Reputation: 2242Reputation: 2242Reputation: 2242Reputation: 2242Reputation: 2242Reputation: 2242Reputation: 2242Reputation: 2242Reputation: 2242
Quote:
Originally Posted by Quirinus View Post
Hello, people.
I'm looking for some article that have relative to "how to be guru in security monitoring".
For example, i'm using splunk + ossec + auditd, monitoring bash history,
I'm not monitoring network (so, any tips about it will be cool). How to example, monitoring linux firewall?

Maybe, any information that can help me detect bad hackers who want to get access to my PC (indicators of compromise).

For me it's shit monitoring and I'm junior in this issue, so any guides will be help me.

Thank you!
Google and other search engines proves a really good search tool for articles on whatever topic.
I am not googling around here pun intended.
 
Old 02-10-2018, 09:08 AM   #3
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
https://www.google.com/search?q=splunk+firewall

Splunk s good on documentation.

I utilized ELK and professionals forward their logs to a centralized server.

"linux firewall" could be elaborated on.
I used https://www.digitalocean.com/community/search?q=ELK
to conquer my logs.
 
Old 02-10-2018, 09:48 AM   #4
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,656

Rep: Reputation: 7970Reputation: 7970Reputation: 7970Reputation: 7970Reputation: 7970Reputation: 7970Reputation: 7970Reputation: 7970Reputation: 7970Reputation: 7970Reputation: 7970
Quote:
Originally Posted by Quirinus View Post
Hello, people.
I'm looking for some article that have relative to "how to be guru in security monitoring". For example, i'm using splunk + ossec + auditd, monitoring bash history, I'm not monitoring network (so, any tips about it will be cool). How to example, monitoring linux firewall?
Which "linux firewall" are you monitoring? There is no 'guide' to security...it's a process. You need to first understand the topic, and it's fairly clear you don't have much of an idea about it now. As habitual stated, Google can get you started.
Quote:
Maybe, any information that can help me detect bad hackers who want to get access to my PC (indicators of compromise).
Again, which PC? Running what services? On what kind of network, behind what firewalls? With what open ports??? Your question is sort of like asking "how high is up?" Without context, it has no meaning.
Quote:
For me it's shit monitoring and I'm junior in this issue, so any guides will be help me.
You need to read the LQ Rules, and quit using profanity. If you want to be more than 'junior in this issue', you need to **LEARN** things. It doesn't appear as if you have a good idea what the topic of computer security entails. Without knowing the basics, you can't learn anything advanced.

Since you probably found THIS site with a Google search, go back there and put things in like "basics of computer security", and learn the CONCEPTS. Build on them, and learn how they apply to different systems/network. Then learn more...and prepare to keep learning the rest of your life, because it is a NEVER ENDING process.

Want to be a 'guru' and keep your computer 100% safe? Lock it in a metal room, and don't ever connect it to a network. Aside from that...you're ALWAYS vulnerable.
 
1 members found this post helpful.
Old 02-10-2018, 11:26 AM   #5
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
Quote:
Originally Posted by Quirinus View Post
Hello, people.
I'm looking for some article that have relative to "how to be guru in security monitoring".
For example, i'm using splunk + ossec + auditd, monitoring bash history,
I'm not monitoring network (so, any tips about it will be cool). How to example, monitoring linux firewall?

Maybe, any information that can help me detect bad hackers who want to get access to my PC (indicators of compromise).

For me it's shit monitoring and I'm junior in this issue, so any guides will be help me.

Thank you!
No network monitoring?
Why is it "shit monitoring"?

Advice: They give the good jobs to those whose do "shit" jobs well.

Good Luck!
 
Old 02-10-2018, 04:49 PM   #6
Trihexagonal
Member
 
Registered: Jul 2017
Posts: 362
Blog Entries: 1

Rep: Reputation: 334Reputation: 334Reputation: 334Reputation: 334
Quote:
Originally Posted by Quirinus View Post
For me it's shit monitoring and I'm junior in this issue, so any guides will be help me.

It's always the hard lessons I remember best.

Think back on this.
 
Old 02-17-2018, 04:12 AM   #7
AwesomeMachine
LQ Guru
 
Registered: Jan 2005
Location: USA and Italy
Distribution: Debian testing/sid; OpenSuSE; Fedora; Mint
Posts: 5,524

Rep: Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015
Have a look at snort. It'll keep you busy for a while.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Linux Security Tips glowkumar Linux - Security 4 08-09-2016 10:09 AM
LXer: Tips for Improving the Linux Desktop Security LXer Syndicated Linux News 0 09-24-2015 09:15 AM
Is there any simple tips for Linux security? greenwinter02 Linux - Security 3 10-23-2007 06:18 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:50 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration