Prelude Manager 0.9.13 (Default branch)


 
Thread Tools Search this Thread
Special Forums News, Links, Events and Announcements Software Releases - RSS News Prelude Manager 0.9.13 (Default branch)
# 1  
Old 06-27-2008
Prelude Manager 0.9.13 (Default branch)

Prelude-Manager is a high-availability server that collects and normalizes information from distributed Prelude-IDS sensors and stores them in a database (or any kind of user-provided media). It is part of Prelude, a hybrid Intrusion Detection framework implementing an open communication layer for use by any security application. Prelude-Manager also provide the ability to relay received events to one or several other prelude-manager servers and allows users to filter received events so they can provide specific actions for specific events. Support for filtering plugins allows users to hook into different places in the Manager to define custom criteria for alert relaying and logging.License: GNU General Public License (GPL)Changes:
libev was updated to 3.42, including a number offixes. The Prelude-Manager-SMTP plugin isincluded, providing the ability to send a textualalert as mail in Prelude-Manager.Image

More...
Login or Register to Ask a Question

Previous Thread | Next Thread
Login or Register to Ask a Question
Prelude(1)							   User Commands							Prelude(1)

NAME
preludedb-admin - tool to copy, move, delete, save or restore a prelude database SYNOPSIS
preludedb-admin copy|move|delete|load|save arguments DESCRIPTION
preludedb-admin can be used to copy, move, delete, save or restore a prelude database, partly or in whole, while preserving IDMEF data con- sistency. Mandatory arguments copy Make a copy of a Prelude database to another database. delete Delete content of a Prelude database. load Load a Prelude database from a file. move Move content of a Prelude database to another database. save Save a Prelude database to a file. Running a command without providing arguments will display a detailed help. EXAMPLES
Obtaining help on a specific command: # preludedb-admin save Usage : save <alert|heartbeat> <database> <filename> [options] Example: preludedb-admin save alert "type=mysql name=dbname user=prelude" outputfile Save messages from <database> into [filename]. If no filename argument is provided, data will be written to standard output. Database arguments: type : Type of database (mysql/pgsql). name : Name of the database. user : User to access the database. pass : Password to access the database. Valid options: --offset <offset> : Skip processing until 'offset' events. --count <count> : Process at most count events. --query-logging [filename] : Log SQL query to the specified file. --criteria <criteria> : Only process events matching criteria. --events-per-transaction : Maximum number of event to process per transaction (default 1000). Preludedb-admin can be useful to delete events from a prelude database : preludedb-admin delete alert --criteria <criteria> "type=<mysql> name=<dbname> user=<prelude-user> pass=<pass>" where criteria is an IDMEF criteria : preludedb-admin delete alert --criteria "alert.classification.text == 'UDP packet dropped'" "type=mysql name=prelude user=prelude-user pass=prelude-pass" This will delete all event with the classification text "UDP packet dropped" from the database. SEE ALSO
The Prelude Handbook: https://trac.prelude-ids.org/wiki/PreludeHandbook Prelude homepage: http://www.prelude-ids.com/ Creating filter using IDMEF Criteria: https://trac.prelude-ids.org/wiki/IDMEFCriteria Prelude IDMEF Path: https://trac.prelude-ids.org/wiki/IDMEFPath BUGS
To report a bug, please visit https://trac.prelude-ids.org/ AUTHOR
This manpage was Written by Pierre Chifflier. COPYRIGHT
Copyright (C) 2006 PreludeIDS Technologies. This is free software. You may redistribute copies of it under the terms of the GNU General Public License <http://www.gnu.org/licenses/gpl.html>. There is NO WARRANTY, to the extent permitted by law. preludedb-admin June 2007 Prelude(1)