{"id":66,"date":"2009-07-27T19:55:54","date_gmt":"2009-07-28T01:55:54","guid":{"rendered":"http:\/\/www.anthonyreinke.com\/?p=66"},"modified":"2009-07-27T19:55:54","modified_gmt":"2009-07-28T01:55:54","slug":"ossec-and-splunk","status":"publish","type":"post","link":"https:\/\/anthonyreinke.com\/index.php\/2009\/07\/27\/ossec-and-splunk\/","title":{"rendered":"OSSEC and Splunk"},"content":{"rendered":"<p>I have been playing with OSSEC and Splunk.\u00a0 OSSEC is a Host based Intrusion Detection System (HIDS).\u00a0 Splunk is a log archiving and searching system.\u00a0 OSSEC is open source and is multiple platform.\u00a0 You can run it on Linux\/Unix and Windows.\u00a0 I am using OSSEC to forward Windows Event Logs to Splunk.\u00a0 Splunk makes the searching and correlation.\u00a0 Splunk can do WMI.\u00a0 This would be great since no agent would need to be installed.\u00a0 The problems is that if you have more than 30-50 systems, the amount time and traffic would cause issues.\u00a0 Using the OSSEC agent, I am able to push the event logs to the OSSEC server.\u00a0 From there the OSSEC server will upload to the Splunk server via Syslog.<\/p>\n<p>Right now I have the servers all talking but I do need to adjust a few things.\u00a0 Right now Splunk sees all the hosts as the OSSEC server.\u00a0 I believe I just need to tweak the fields.\u00a0 The question is how.<\/p>\n<p>Splunk<br \/>\n<a title=\"Splunk\" href=\"http:\/\/www.splunk.com\" target=\"_blank\">http:\/\/www.splunk.com<\/a><\/p>\n<p>OSSEC<br \/>\n<a title=\"OSSEC\" href=\"http:\/\/www.ossec.net\" target=\"_blank\">http:\/\/www.ossec.net<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>I have been playing with OSSEC and Splunk.\u00a0 OSSEC is a Host based Intrusion Detection System (HIDS).\u00a0 Splunk is a log archiving and searching system.\u00a0 OSSEC is open source and is multiple platform.\u00a0 You can run it on Linux\/Unix and Windows.\u00a0 I am using OSSEC to forward Windows Event Logs to Splunk.\u00a0 Splunk makes the [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-66","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/anthonyreinke.com\/index.php\/wp-json\/wp\/v2\/posts\/66","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/anthonyreinke.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/anthonyreinke.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/anthonyreinke.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/anthonyreinke.com\/index.php\/wp-json\/wp\/v2\/comments?post=66"}],"version-history":[{"count":0,"href":"https:\/\/anthonyreinke.com\/index.php\/wp-json\/wp\/v2\/posts\/66\/revisions"}],"wp:attachment":[{"href":"https:\/\/anthonyreinke.com\/index.php\/wp-json\/wp\/v2\/media?parent=66"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/anthonyreinke.com\/index.php\/wp-json\/wp\/v2\/categories?post=66"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/anthonyreinke.com\/index.php\/wp-json\/wp\/v2\/tags?post=66"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}