套件： sagan-rules (10212010-r1-1)
- 主頁 [sagan.softwink.com]
Real-time System & Event Log Monitoring System [rules]
Sagan is a multi-threaded, real time system- and event-log monitoring system, but with a twist. Sagan uses a “Snort” like rule set for detecting malicious events happening on your network and/or computer systems. If Sagan detects a potentially bad event, that event can be stored to a Snort database (MySQL/PostgreSQL), send it to a SIEM tool like Prelude, or send an email.
This package provides the rules for Sagan.