securityonion-rule-update - 20151201-1ubuntu1securityonion19 is now available for Security Onion! This package should resolve the following issues:
rule-update ossec backup local rules issue #1572
https://github.com/Security-Onion-Solutions/security-onion/issues/1572
rule-update: if non-master and salt is enabled, then just run state.highstate #1574
https://github.com/Security-Onion-Solutions/security-onion/issues/1574
rule-update: Add white_list.rules and black_list.rules to worker sync #1577
https://github.com/Security-Onion-Solutions/security-onion/issues/1577
Thanks
Thanks to Matt Svensson for submitting the following Pull Request:
https://github.com/Security-Onion-Solutions/securityonion-rule-update/pull/9
Thanks to Wes Lambert for testing!
Updating
Please see the following page for full update instructions:
https://securityonion.net/docs/Upgrade
Conference
Registration is now open for Security Onion Conference 2019 on Friday, October 4, 2019!
https://socaugusta2019.eventbrite.com/
Documentation
We've got a brand new documentation site! Please let us know if anything needs to be updated:
https://securityonion.net/docs
Also, we're now offering a printed copy of our official documentation with foreword by Richard Bejtlich and proceeds going to Rural Technology Fund!
https://securityonion.net/book
Training
Security Onion Solutions is the only official authorized training provider for Security Onion and we have 4-day Security Onion Training classes coming up in Columbia MD and Augusta GA! If you can't make it to an onsite class, we have a new online training platform. For more information and other training options, please see:
https://securityonionsolutions.com
Appliances
We now offer hardware appliances! For more information, please see:
https://blog.securityonion.net/2018/10/introducing-security-onion-solutions.html
Support
Need support? Please see:
https://securityonion.net/docs/Support
Thanks!
Showing posts with label ossec. Show all posts
Showing posts with label ossec. Show all posts
Thursday, July 25, 2019
Tuesday, July 2, 2019
securityonion-sostat - 20120722-0ubuntu0securityonion128 now available for Security Onion!
securityonion-sostat - 20120722-0ubuntu0securityonion128 is now available for Security Onion! This package should resolve the following issues:
soup: if snort or suricata are updated, remind user to run rule-update #1536
https://github.com/Security-Onion-Solutions/security-onion/issues/1536
soup: if Wazuh is updated, remind user to review ossec.conf and update Wazuh agents #1544
https://github.com/Security-Onion-Solutions/security-onion/issues/1544
Thanks
Thanks to Wes Lambert for testing!
Updating
Please see the following page for full update instructions:
https://securityonion.net/docs/Upgrade
Conference
Please mark your calendar! Security Onion Conference 2019 will be on Friday, October 4, 2019 and registration will open July 18!
https://securityonion.net/conference
Documentation
We've got a brand new documentation site! Please let us know if anything needs to be updated:
https://securityonion.net/docs
Also, we're now offering a printed copy of our official documentation with foreword by Richard Bejtlich and proceeds going to Rural Technology Fund:
https://securityonion.net/book
Training
We have 4-day Security Onion Training classes coming up in Columbia MD and Augusta GA! If you can't make it to an onsite class, we have a new online training platform. For more information and other training options, please see:
https://securityonionsolutions.com
Appliances
We now offer hardware appliances! For more information, please see:
https://blog.securityonion.net/2018/10/introducing-security-onion-solutions.html
Support
Need support? Please see:
https://securityonion.net/docs/Support
Thanks!
soup: if snort or suricata are updated, remind user to run rule-update #1536
https://github.com/Security-Onion-Solutions/security-onion/issues/1536
soup: if Wazuh is updated, remind user to review ossec.conf and update Wazuh agents #1544
https://github.com/Security-Onion-Solutions/security-onion/issues/1544
Thanks
Thanks to Wes Lambert for testing!
Updating
Please see the following page for full update instructions:
https://securityonion.net/docs/Upgrade
Conference
Please mark your calendar! Security Onion Conference 2019 will be on Friday, October 4, 2019 and registration will open July 18!
https://securityonion.net/conference
Documentation
We've got a brand new documentation site! Please let us know if anything needs to be updated:
https://securityonion.net/docs
Also, we're now offering a printed copy of our official documentation with foreword by Richard Bejtlich and proceeds going to Rural Technology Fund:
https://securityonion.net/book
Training
We have 4-day Security Onion Training classes coming up in Columbia MD and Augusta GA! If you can't make it to an onsite class, we have a new online training platform. For more information and other training options, please see:
https://securityonionsolutions.com
Appliances
We now offer hardware appliances! For more information, please see:
https://blog.securityonion.net/2018/10/introducing-security-onion-solutions.html
Support
Need support? Please see:
https://securityonion.net/docs/Support
Thanks!
Monday, February 25, 2019
Wazuh 3.8.2 now available for Security Onion!
The following packages are now available:
Wazuh 3.8.2 (packaged as ossec-hids-server - 3.8.2.2ubuntu1securityonion1)
securityonion-ossec-rules - 20120726-0ubuntu0securityonion12
This should resolve the following issues:
Wazuh 3.8.2 #1422
https://github.com/Security-Onion-Solutions/security-onion/issues/1422
Wazuh email config not being migrated properly #1441
https://github.com/Security-Onion-Solutions/security-onion/issues/1441
securityonion-ossec-rules: ignore alerts on common files #1455
https://github.com/Security-Onion-Solutions/security-onion/issues/1455
Thanks
Thanks to the Wazuh team for Wazuh 3.8.2!
Thanks to Wes Lambert for testing!
Updating
Please see the following page for full update instructions:
https://securityonion.net/docs/Upgrade
Training
We have a 4-day Security Onion training class coming up in Columbia MD! If you can't make it to this onsite class, we have a new online training platform! For more information and other training options, please see:
https://securityonionsolutions.com
Appliances
We now offer hardware appliances! For more information, please see:
https://blog.securityonion.net/2018/10/introducing-security-onion-solutions.html
Documentation
We've got a brand new documentation site! Please let us know if anything needs to be updated.
https://securityonion.net/docs
Support
Need support? Please see:
https://securityonion.net/docs/Support
Thanks!
Wazuh 3.8.2 (packaged as ossec-hids-server - 3.8.2.2ubuntu1securityonion1)
securityonion-ossec-rules - 20120726-0ubuntu0securityonion12
This should resolve the following issues:
Wazuh 3.8.2 #1422
https://github.com/Security-Onion-Solutions/security-onion/issues/1422
Wazuh email config not being migrated properly #1441
https://github.com/Security-Onion-Solutions/security-onion/issues/1441
securityonion-ossec-rules: ignore alerts on common files #1455
https://github.com/Security-Onion-Solutions/security-onion/issues/1455
Thanks
Thanks to the Wazuh team for Wazuh 3.8.2!
Thanks to Wes Lambert for testing!
Updating
Please see the following page for full update instructions:
https://securityonion.net/docs/Upgrade
Training
We have a 4-day Security Onion training class coming up in Columbia MD! If you can't make it to this onsite class, we have a new online training platform! For more information and other training options, please see:
https://securityonionsolutions.com
Appliances
We now offer hardware appliances! For more information, please see:
https://blog.securityonion.net/2018/10/introducing-security-onion-solutions.html
Documentation
We've got a brand new documentation site! Please let us know if anything needs to be updated.
https://securityonion.net/docs
Support
Need support? Please see:
https://securityonion.net/docs/Support
Thanks!
Wednesday, January 2, 2019
Wazuh 3.7.2 now available for Security Onion!
The following packages are now available:
Wazuh 3.7.2 (packaged as ossec-hids-server - 3.7.2.2-ubuntu1securityonion1)
securityonion-ossec-rules - 20120726-0ubuntu0securityonion11
These packages should resolve the following issues:
Wazuh 3.7.2 #1400
https://github.com/Security-Onion-Solutions/security-onion/issues/1400
securityonion-ossec-rules: ignore 401 for Kibana and Squert #1408
https://github.com/Security-Onion-Solutions/security-onion/issues/1408
Thanks
Thanks to the Wazuh team for Wazuh 3.7.2!
Thanks to Wes Lambert for testing!
Updating
Please see the following page for full update instructions:
https://securityonion.net/wiki/Upgrade
Training
We have 4-day Security Onion training classes coming up in San Antonio, Texas and Atlanta, Georgia! If you can't make it to either of these onsite classes, we have a new online training platform! For more information and other training options, please see:
https://securityonionsolutions.com
Appliances
We now offer hardware appliances! For more information, please see:
https://blog.securityonion.net/2018/10/introducing-security-onion-solutions.html
Support
Need support? Please see:
https://securityonion.net/wiki/Support
Thanks!
Wazuh 3.7.2 (packaged as ossec-hids-server - 3.7.2.2-ubuntu1securityonion1)
securityonion-ossec-rules - 20120726-0ubuntu0securityonion11
These packages should resolve the following issues:
Wazuh 3.7.2 #1400
https://github.com/Security-Onion-Solutions/security-onion/issues/1400
securityonion-ossec-rules: ignore 401 for Kibana and Squert #1408
https://github.com/Security-Onion-Solutions/security-onion/issues/1408
Thanks
Thanks to the Wazuh team for Wazuh 3.7.2!
Thanks to Wes Lambert for testing!
Updating
Please see the following page for full update instructions:
https://securityonion.net/wiki/Upgrade
Training
We have 4-day Security Onion training classes coming up in San Antonio, Texas and Atlanta, Georgia! If you can't make it to either of these onsite classes, we have a new online training platform! For more information and other training options, please see:
https://securityonionsolutions.com
Appliances
We now offer hardware appliances! For more information, please see:
https://blog.securityonion.net/2018/10/introducing-security-onion-solutions.html
Support
Need support? Please see:
https://securityonion.net/wiki/Support
Thanks!
Tuesday, December 11, 2018
Wazuh 3.7.1 now available for Security Onion 16.04!
The following are now available for Security Onion 16.04:
Wazuh 3.7.1 (packaged as ossec-hids-server - 3.7.1.3-ubuntu1securityonion1)
securityonion-ossec-rules - 20120726-0ubuntu0securityonion10
This should resolve the following issues:
Wazuh 3.7.1 #1363
https://github.com/Security-Onion-Solutions/security-onion/issues/1363
ossec-hids-server: include local_rules.xml #1345
https://github.com/Security-Onion-Solutions/security-onion/issues/1345
ossec-hids-server: ossec-init.conf #1360
https://github.com/Security-Onion-Solutions/security-onion/issues/1360
ossec-hids-server: fix ownership and perms on /var/ossec/var/db and /var/ossec/var/multigroups #1392
https://github.com/Security-Onion-Solutions/security-onion/issues/1392
ossec-hids-server: postinst should check for symlinks before creating them #1393
https://github.com/Security-Onion-Solutions/security-onion/issues/1393
ossec-hids-server: errors relating to syscheck sqlite database #1394
https://github.com/Security-Onion-Solutions/security-onion/issues/1394
securityonion-ossec-rules: do not alert on known file addition/deletion in /etc/nsm/rules/backup/ or /etc/nsm/backup/ #1346
https://github.com/Security-Onion-Solutions/security-onion/issues/1346
securityonion-ossec-rules: detect apache auth failure correctly #1391
https://github.com/Security-Onion-Solutions/security-onion/issues/1391
Thanks
Thanks to the Wazuh team for Wazuh 3.7.1!
Thanks to Wes Lambert for testing!
Updating
Please see the following page for full update instructions:
https://securityonion.net/wiki/Upgrade
Training
We have 4-day Security Onion training classes coming up in San Antonio, Texas and Atlanta, Georgia! If you can't make it to either of these onsite classes, we have a new online training platform! For more information and other training options, please see:
https://securityonionsolutions.com
Appliances
We now offer hardware appliances! For more information, please see:
https://blog.securityonion.net/2018/10/introducing-security-onion-solutions.html
Support
Need support? Please see:
https://securityonion.net/wiki/Support
Thanks!
Wazuh 3.7.1 (packaged as ossec-hids-server - 3.7.1.3-ubuntu1securityonion1)
securityonion-ossec-rules - 20120726-0ubuntu0securityonion10
This should resolve the following issues:
Wazuh 3.7.1 #1363
https://github.com/Security-Onion-Solutions/security-onion/issues/1363
ossec-hids-server: include local_rules.xml #1345
https://github.com/Security-Onion-Solutions/security-onion/issues/1345
ossec-hids-server: ossec-init.conf #1360
https://github.com/Security-Onion-Solutions/security-onion/issues/1360
ossec-hids-server: fix ownership and perms on /var/ossec/var/db and /var/ossec/var/multigroups #1392
https://github.com/Security-Onion-Solutions/security-onion/issues/1392
ossec-hids-server: postinst should check for symlinks before creating them #1393
https://github.com/Security-Onion-Solutions/security-onion/issues/1393
ossec-hids-server: errors relating to syscheck sqlite database #1394
https://github.com/Security-Onion-Solutions/security-onion/issues/1394
securityonion-ossec-rules: do not alert on known file addition/deletion in /etc/nsm/rules/backup/ or /etc/nsm/backup/ #1346
https://github.com/Security-Onion-Solutions/security-onion/issues/1346
securityonion-ossec-rules: detect apache auth failure correctly #1391
https://github.com/Security-Onion-Solutions/security-onion/issues/1391
Thanks
Thanks to the Wazuh team for Wazuh 3.7.1!
Thanks to Wes Lambert for testing!
Updating
Please see the following page for full update instructions:
https://securityonion.net/wiki/Upgrade
Training
We have 4-day Security Onion training classes coming up in San Antonio, Texas and Atlanta, Georgia! If you can't make it to either of these onsite classes, we have a new online training platform! For more information and other training options, please see:
https://securityonionsolutions.com
Appliances
We now offer hardware appliances! For more information, please see:
https://blog.securityonion.net/2018/10/introducing-security-onion-solutions.html
Support
Need support? Please see:
https://securityonion.net/wiki/Support
Thanks!
Monday, October 1, 2018
Wazuh 3.6.1, Elastic 6.4.1, and associated components are now available for Security Onion 16.04!
The following are now available for Security Onion 14.04 and 16.04:
Elastic 6.4.1 and associated Docker images
The following are now available for Security Onion 16.04:
Wazuh 3.6.1 (packaged as ossec-hids-server - 3.6.1.23-ubuntu1securityonion1)
securityonion-elastic - 20180130-1ubuntu1securityonion137
securityonion-setup - 20120912-0ubuntu0securityonion277
securityonion-sguil-agent-ossec - 20120726-0ubuntu0securityonion19
This should resolve the following issues:
Issue 708: Wazuh 3.6.1
https://github.com/Security-Onion-Solutions/security-onion/issues/708
Issue 707: OSSEC: add decoders/rules for sysmon
https://github.com/Security-Onion-Solutions/security-onion/issues/707
Issue 852: OSSEC: remove Snorby logs from ossec.conf
https://github.com/Security-Onion-Solutions/security-onion/issues/852
Issue 1328: securityonion-sguil-agent-ossec: update for Wazuh
https://github.com/Security-Onion-Solutions/security-onion/issues/1328
Issue 1329: securityonion-elastic: update for Wazuh
https://github.com/Security-Onion-Solutions/security-onion/issues/1329
Issue 1315: securityonion-elastic: so-elastic-reset workaround disabled wildcard delete
https://github.com/Security-Onion-Solutions/security-onion/issues/1315
Issue 1319: securityonion-elastic: add ES node listing and removal scripts
https://github.com/Security-Onion-Solutions/security-onion/issues/1319
Issue 1327: securityonion-elastic: increase default logstash heap for Eval Mode
https://github.com/Security-Onion-Solutions/security-onion/issues/1327
Issue 1330: so-allow: allowing an OSSEC agent should allow both UDP and TCP traffic
https://github.com/Security-Onion-Solutions/security-onion/issues/1330
Issue 1331: Elastic 6.4.1
https://github.com/Security-Onion-Solutions/security-onion/issues/1331
Thanks
Thanks to the Wazuh team for Wazuh 3.6.1!
Thanks to the Elastic team for Elastic 6.4.1!
Thanks to Wes Lambert for his work on these updates!
Updating
Please see the following page for full update instructions:
https://securityonion.net/wiki/Upgrade
Conference
Registration is now open for our annual Security Onion Conference in Augusta GA!
http://socaugusta2018.eventbrite.com/
Training
We have a 4-day Security Onion training class coming up in Augusta, Georgia! If you can't make it to this onsite class, we have a new online training platform! For more information and other training options, please see:
https://securityonionsolutions.com
Support
Need support? Please see:
https://securityonion.net/wiki/Support
Thanks!
Elastic 6.4.1 and associated Docker images
The following are now available for Security Onion 16.04:
Wazuh 3.6.1 (packaged as ossec-hids-server - 3.6.1.23-ubuntu1securityonion1)
securityonion-elastic - 20180130-1ubuntu1securityonion137
securityonion-setup - 20120912-0ubuntu0securityonion277
securityonion-sguil-agent-ossec - 20120726-0ubuntu0securityonion19
| Wazuh can analyze sysmon logs and generate HIDS alerts |
This should resolve the following issues:
Issue 708: Wazuh 3.6.1
https://github.com/Security-Onion-Solutions/security-onion/issues/708
Issue 707: OSSEC: add decoders/rules for sysmon
https://github.com/Security-Onion-Solutions/security-onion/issues/707
Issue 852: OSSEC: remove Snorby logs from ossec.conf
https://github.com/Security-Onion-Solutions/security-onion/issues/852
Issue 1328: securityonion-sguil-agent-ossec: update for Wazuh
https://github.com/Security-Onion-Solutions/security-onion/issues/1328
Issue 1329: securityonion-elastic: update for Wazuh
https://github.com/Security-Onion-Solutions/security-onion/issues/1329
Issue 1315: securityonion-elastic: so-elastic-reset workaround disabled wildcard delete
https://github.com/Security-Onion-Solutions/security-onion/issues/1315
Issue 1319: securityonion-elastic: add ES node listing and removal scripts
https://github.com/Security-Onion-Solutions/security-onion/issues/1319
Issue 1327: securityonion-elastic: increase default logstash heap for Eval Mode
https://github.com/Security-Onion-Solutions/security-onion/issues/1327
Issue 1330: so-allow: allowing an OSSEC agent should allow both UDP and TCP traffic
https://github.com/Security-Onion-Solutions/security-onion/issues/1330
Issue 1331: Elastic 6.4.1
https://github.com/Security-Onion-Solutions/security-onion/issues/1331
Thanks
Thanks to the Wazuh team for Wazuh 3.6.1!
Thanks to the Elastic team for Elastic 6.4.1!
Thanks to Wes Lambert for his work on these updates!
Updating
Please see the following page for full update instructions:
https://securityonion.net/wiki/Upgrade
Conference
Registration is now open for our annual Security Onion Conference in Augusta GA!
http://socaugusta2018.eventbrite.com/
Training
We have a 4-day Security Onion training class coming up in Augusta, Georgia! If you can't make it to this onsite class, we have a new online training platform! For more information and other training options, please see:
https://securityonionsolutions.com
Support
Need support? Please see:
https://securityonion.net/wiki/Support
Thanks!
Friday, July 10, 2015
New securityonion-sguil-agent-ossec package resolves an issue
Brian Kellogg sent in a patch for the securityonion-sguil-agent-ossec package to parse syslog IP addresses. Thanks, Brian!
The new package version is as follows:
securityonion-sguil-agent-ossec - 20120726-0ubuntu0securityonion16
Issues Resolved
ossec_agent: Add source of syslog as destination IP for Sguil alert #760
https://github.com/Security-Onion-Solutions/security-onion/issues/760
Updating
This new package is now available in our stable repo. Please see the following page for full update instructions:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Upgrade
Feedback
If you have any questions or problems, please use our security-onion mailing list:
https://github.com/Security-Onion-Solutions/security-onion/wiki/MailingLists
Training
Need training? Please see:
http://securityonionsolutions.com
Commercial Support
Need commercial support? Please see:
http://securityonionsolutions.com
Help Wanted
If you and/or your organization have found value in Security Onion, please consider giving back to the community by joining one of our teams:
https://github.com/Security-Onion-Solutions/security-onion/wiki/TeamMembers
Thanks!
The new package version is as follows:
securityonion-sguil-agent-ossec - 20120726-0ubuntu0securityonion16
Issues Resolved
ossec_agent: Add source of syslog as destination IP for Sguil alert #760
https://github.com/Security-Onion-Solutions/security-onion/issues/760
Updating
This new package is now available in our stable repo. Please see the following page for full update instructions:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Upgrade
Feedback
If you have any questions or problems, please use our security-onion mailing list:
https://github.com/Security-Onion-Solutions/security-onion/wiki/MailingLists
Training
Need training? Please see:
http://securityonionsolutions.com
Commercial Support
Need commercial support? Please see:
http://securityonionsolutions.com
Help Wanted
If you and/or your organization have found value in Security Onion, please consider giving back to the community by joining one of our teams:
https://github.com/Security-Onion-Solutions/security-onion/wiki/TeamMembers
Thanks!
Monday, June 29, 2015
OSSEC 2.8.2 now available!
OSSEC 2.8.2 was recently released:
http://www.ossec.net/?p=1198
I've packaged OSSEC 2.8.2 and the new package version is as follows:
ossec-hids-server - 2.8.2-ubuntu10securityonion2
The new package has been tested by the following (thanks!):
James Taylor
Shane Castle
Issues Resolved
Issue 745: OSSEC 2.8.2
https://github.com/Security-Onion-Solutions/security-onion/issues/745
Updating
This new package is now available in our stable repo. Please see the following page for full update instructions:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Upgrade
After installing the new OSSEC package, you'll need to double-check /var/ossec/etc/ossec.conf and add back any local customizations. You can then restart OSSEC as follows:
Feedback
If you have any questions or problems, please use our security-onion mailing list:
https://github.com/Security-Onion-Solutions/security-onion/wiki/MailingLists
Training
Need training? Please see:
http://securityonionsolutions.com
Commercial Support
Need commercial support? Please see:
http://securityonionsolutions.com
Help Wanted
If you and/or your organization have found value in Security Onion, please consider giving back to the community by joining one of our teams:
https://github.com/Security-Onion-Solutions/security-onion/wiki/TeamMembers
Thanks!
http://www.ossec.net/?p=1198
I've packaged OSSEC 2.8.2 and the new package version is as follows:
ossec-hids-server - 2.8.2-ubuntu10securityonion2
The new package has been tested by the following (thanks!):
James Taylor
Shane Castle
Issues Resolved
Issue 745: OSSEC 2.8.2
https://github.com/Security-Onion-Solutions/security-onion/issues/745
Updating
This new package is now available in our stable repo. Please see the following page for full update instructions:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Upgrade
After installing the new OSSEC package, you'll need to double-check /var/ossec/etc/ossec.conf and add back any local customizations. You can then restart OSSEC as follows:
sudo service ossec-hids-server restart
Feedback
If you have any questions or problems, please use our security-onion mailing list:
https://github.com/Security-Onion-Solutions/security-onion/wiki/MailingLists
Training
Need training? Please see:
http://securityonionsolutions.com
Commercial Support
Need commercial support? Please see:
http://securityonionsolutions.com
Help Wanted
If you and/or your organization have found value in Security Onion, please consider giving back to the community by joining one of our teams:
https://github.com/Security-Onion-Solutions/security-onion/wiki/TeamMembers
Thanks!
Thursday, May 21, 2015
New securityonion-sguil-agent-ossec package resolves three issues
Brian Kellogg sent some patches for our ossec_agent for Sguil and I've updated the package. The new package has been tested by David Zawdie and Brian Kellogg (thanks!).
The new package version is:
securityonion-sguil-agent-ossec - 20120726-0ubuntu0securityonion15
Issues Resolved
Issue 705: ossec_agent: improvements from Brian Kellogg
https://github.com/Security-Onion-Solutions/security-onion/issues/705
Issue 716: ossec_agent: tighten regex to only look for -> anchored to hostname or IP
https://github.com/Security-Onion-Solutions/security-onion/issues/716
Issue 717: ossec_agent: send alerts to sguild immediately instead of waiting for next alert
https://github.com/Security-Onion-Solutions/security-onion/issues/717
Updating
The new package is now available in our stable repo. Please see the following page for full update instructions:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Upgrade
Feedback
If you have any questions or problems, please use our security-onion mailing list:
https://github.com/Security-Onion-Solutions/security-onion/wiki/MailingLists
Training
Need training? We have 3-hour online classes this week:
http://securityonionsolutions.com
Commercial Support
Need commercial support? Please see:
http://securityonionsolutions.com
Help Wanted
If you and/or your organization have found value in Security Onion, please consider giving back to the community by joining one of our teams:
https://github.com/Security-Onion-Solutions/security-onion/wiki/TeamMembers
Thanks!
The new package version is:
securityonion-sguil-agent-ossec - 20120726-0ubuntu0securityonion15
Issues Resolved
Issue 705: ossec_agent: improvements from Brian Kellogg
https://github.com/Security-Onion-Solutions/security-onion/issues/705
Issue 716: ossec_agent: tighten regex to only look for -> anchored to hostname or IP
https://github.com/Security-Onion-Solutions/security-onion/issues/716
Issue 717: ossec_agent: send alerts to sguild immediately instead of waiting for next alert
https://github.com/Security-Onion-Solutions/security-onion/issues/717
Updating
The new package is now available in our stable repo. Please see the following page for full update instructions:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Upgrade
Feedback
If you have any questions or problems, please use our security-onion mailing list:
https://github.com/Security-Onion-Solutions/security-onion/wiki/MailingLists
Training
Need training? We have 3-hour online classes this week:
http://securityonionsolutions.com
Commercial Support
Need commercial support? Please see:
http://securityonionsolutions.com
Help Wanted
If you and/or your organization have found value in Security Onion, please consider giving back to the community by joining one of our teams:
https://github.com/Security-Onion-Solutions/security-onion/wiki/TeamMembers
Thanks!
Tuesday, March 31, 2015
Four package updates
I've updated four packages to resolve a few issues and these new packages have been tested by Josh Brower (thanks!).
The new package version are as follows:
securityonion-setup - 20120912-0ubuntu0securityonion132
securityonion-sostat - 20120722-0ubuntu0securityonion33
securityonion-web-page - 20141015-0ubuntu0securityonion22
securityonion-elsa-extras - 20131117-1ubuntu0securityonion58
Issues Resolved
Issue 703: Move from Google Code to Github
https://github.com/Security-Onion-Solutions/security-onion/issues/703
Security Onion has moved to Github, so some of the hyperlinks in Setup and sostat had to be updated.
Issue 706: Add Josh Brower's ELSA parsers for process logs and sysmon
https://github.com/Security-Onion-Solutions/security-onion/issues/706
If you have Windows machines with OSSEC agents on them and process auditing enabled, ELSA now parses those "new process" logs.
Issue 709: Add fear.nothing's ELSA parsers for pfSense
https://github.com/Security-Onion-Solutions/security-onion/issues/709
If you're running pfSense firewalls and send their logs to Security Onion via syslog, ELSA will now parse them.
Issue 710: securityonion-web-page: add ELSA queries for Firewall logs
and Windows Processes
https://github.com/Security-Onion-Solutions/security-onion/issues/710
Since ELSA is now parsing firewall logs and Windows processes, we provide some additional ELSA queries to slice and dice those logs. See screenshots below.
Screenshots
Updating
The new packages are now available in our stable repo. Please see the following page for full update instructions:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Upgrade
Feedback
If you have any questions or problems, please use our security-onion mailing list:
https://github.com/Security-Onion-Solutions/security-onion/wiki/MailingLists
Training
Need training? We have 3-hour online classes and also a 4-day onsite class coming up in Houston. Please see:
http://securityonionsolutions.com
Commercial Support
Need commercial support? Please see:
http://securityonionsolutions.com
Help Wanted
If you and/or your organization have found value in Security Onion, please consider giving back to the community by joining one of our teams:
https://github.com/Security-Onion-Solutions/security-onion/wiki/TeamMembers
Thanks!
The new package version are as follows:
securityonion-setup - 20120912-0ubuntu0securityonion132
securityonion-sostat - 20120722-0ubuntu0securityonion33
securityonion-web-page - 20141015-0ubuntu0securityonion22
securityonion-elsa-extras - 20131117-1ubuntu0securityonion58
Issues Resolved
Issue 703: Move from Google Code to Github
https://github.com/Security-Onion-Solutions/security-onion/issues/703
Security Onion has moved to Github, so some of the hyperlinks in Setup and sostat had to be updated.
Issue 706: Add Josh Brower's ELSA parsers for process logs and sysmon
https://github.com/Security-Onion-Solutions/security-onion/issues/706
If you have Windows machines with OSSEC agents on them and process auditing enabled, ELSA now parses those "new process" logs.
Issue 709: Add fear.nothing's ELSA parsers for pfSense
https://github.com/Security-Onion-Solutions/security-onion/issues/709
If you're running pfSense firewalls and send their logs to Security Onion via syslog, ELSA will now parse them.
Issue 710: securityonion-web-page: add ELSA queries for Firewall logs
and Windows Processes
https://github.com/Security-Onion-Solutions/security-onion/issues/710
Since ELSA is now parsing firewall logs and Windows processes, we provide some additional ELSA queries to slice and dice those logs. See screenshots below.
Screenshots
![]() |
| Host Logs - Windows Processes |
![]() |
| Firewall - Top SRC IPs Allowed |
![]() |
| Firewall - Top DST IPs Allowed |
![]() |
| Firewall - Top SRC IPs Denied |
![]() |
| Firewall - Top DST IPs Denied |
Updating
The new packages are now available in our stable repo. Please see the following page for full update instructions:
https://github.com/Security-Onion-Solutions/security-onion/wiki/Upgrade
Feedback
If you have any questions or problems, please use our security-onion mailing list:
https://github.com/Security-Onion-Solutions/security-onion/wiki/MailingLists
Training
Need training? We have 3-hour online classes and also a 4-day onsite class coming up in Houston. Please see:
http://securityonionsolutions.com
Commercial Support
Need commercial support? Please see:
http://securityonionsolutions.com
Help Wanted
If you and/or your organization have found value in Security Onion, please consider giving back to the community by joining one of our teams:
https://github.com/Security-Onion-Solutions/security-onion/wiki/TeamMembers
Thanks!
Wednesday, February 4, 2015
New NSM and ossec_agent.tcl packages resolve several issues
Brian Kellogg submitted a patch for ossec_agent.tcl that allows you to enable or disable DNS lookups. Thanks, Brian! I've packaged this and also updated the NSM package to resolve several issues.
The new packages are as follows:
securityonion-nsmnow-admin-scripts - 20120724-0ubuntu0securityonion114
securityonion-sguil-agent-ossec - 20120726-0ubuntu0securityonion7
These new packages should resolve the following issues:
Issue 684: NSM: nsm_server_ps-start needs to create /var/log/sguild/ if it doesn't already exist
https://code.google.com/p/security-onion/issues/detail?id=684
Issue 686: NSM: nsm_server_ps-start needs to set permissions on /var/log/nsm/so-elsa/ properly
https://code.google.com/p/security-onion/issues/detail?id=686
Issue 687: NSM: nsm_sensor_ps-start should set permissions on /var/log/nsm/HOSTNAME-INTERFACE/ properly
https://code.google.com/p/security-onion/issues/detail?id=687
Issue 689: NSM: add USE_DNS option to ossec_agent.conf
https://code.google.com/p/security-onion/issues/detail?id=689
Issue 688: ossec_agent: add option to disable DNS lookups
https://code.google.com/p/security-onion/issues/detail?id=688
These new packages have been tested by David Zawdie (thanks!).
Release Notes
After updating to the new packages, the next time that the NSM scripts start ossec_agent.tcl, they will add a new USE_DNS option to /etc/nsm/ossec/ossec_agent.conf and default it to 0 (disabled). This results in much better performance for ossec_agent.tcl.
If you need to revert to the previous behavior of DNS lookups enabled and don't mind the additional lookup delay, you can change USE_DNS to 1 (enabled) and then restart ossec_agent.tcl:
Updating
The new packages are now available in our stable repo. Please see the following page for full update instructions:
https://code.google.com/p/security-onion/wiki/Upgrade
Feedback
If you have any questions or problems, please use our security-onion mailing list:
https://code.google.com/p/security-onion/wiki/MailingLists
Commercial Support
Need training and/or commercial support? Please see:
http://securityonionsolutions.com
Help Wanted
If you and/or your organization have found value in Security Onion, please consider giving back to the community by joining one of our teams:
https://code.google.com/p/security-onion/wiki/TeamMembers
Want to show your support for Security Onion?
Several folks have asked about Security Onion t-shirts and they are now available in our CafePress store!
http://www.cafepress.com/securityonion/11820053
Thanks!
The new packages are as follows:
securityonion-nsmnow-admin-scripts - 20120724-0ubuntu0securityonion114
securityonion-sguil-agent-ossec - 20120726-0ubuntu0securityonion7
These new packages should resolve the following issues:
Issue 684: NSM: nsm_server_ps-start needs to create /var/log/sguild/ if it doesn't already exist
https://code.google.com/p/security-onion/issues/detail?id=684
https://code.google.com/p/security-onion/issues/detail?id=686
Issue 687: NSM: nsm_sensor_ps-start should set permissions on /var/log/nsm/HOSTNAME-INTERFACE/ properly
https://code.google.com/p/security-onion/issues/detail?id=687
https://code.google.com/p/security-onion/issues/detail?id=689
Issue 688: ossec_agent: add option to disable DNS lookups
https://code.google.com/p/security-onion/issues/detail?id=688
These new packages have been tested by David Zawdie (thanks!).
Release Notes
After updating to the new packages, the next time that the NSM scripts start ossec_agent.tcl, they will add a new USE_DNS option to /etc/nsm/ossec/ossec_agent.conf and default it to 0 (disabled). This results in much better performance for ossec_agent.tcl.
If you need to revert to the previous behavior of DNS lookups enabled and don't mind the additional lookup delay, you can change USE_DNS to 1 (enabled) and then restart ossec_agent.tcl:
sudo nsm_sensor_ps-restart --only-ossec-agentAlso note that these packages move ossec_agent.tcl to /usr/bin/.
Updating
The new packages are now available in our stable repo. Please see the following page for full update instructions:
https://code.google.com/p/security-onion/wiki/Upgrade
Feedback
If you have any questions or problems, please use our security-onion mailing list:
https://code.google.com/p/security-onion/wiki/MailingLists
Commercial Support
Need training and/or commercial support? Please see:
http://securityonionsolutions.com
Help Wanted
If you and/or your organization have found value in Security Onion, please consider giving back to the community by joining one of our teams:
https://code.google.com/p/security-onion/wiki/TeamMembers
Want to show your support for Security Onion?
Several folks have asked about Security Onion t-shirts and they are now available in our CafePress store!
http://www.cafepress.com/securityonion/11820053
Thanks!
Wednesday, October 29, 2014
Sguil 0.9 and Squert 1.5.0 now available!
Sguil 0.9 and Squert 1.5.0 were recently released:
http://sourceforge.net/p/sguil/mailman/message/32230854/
http://www.squertproject.org/summaryofchangesforsquertversion130
http://www.squertproject.org/summaryofchangesforsquertversion140
http://www.squertproject.org/summaryofchangesforsquertversion150
I've updated our packages to include both of these releases. The new package versions are as follows:
securityonion-capme - 20121213-0ubuntu0securityonion20
securityonion-http-agent - 0.3.1-0ubuntu0securityonion6
securityonion-nsmnow-admin-scripts - 20120724-0ubuntu0securityonion88
securityonion-ossec-rules - 20120726-0ubuntu0securityonion4
securityonion-setup - 20120912-0ubuntu0securityonion125
securityonion-sguil-agent-ossec - 20120726-0ubuntu0securityonion4
securityonion-sguil-client - 20141004-0ubuntu0securityonion7
securityonion-sguil-sensor - 20141004-0ubuntu0securityonion7
securityonion-sguil-server - 20141004-0ubuntu0securityonion7
securityonion-squert - 20141015-0ubuntu0securityonion3
Issues Resolved
Issue 287: Sguil 0.9
https://code.google.com/p/security-onion/issues/detail?id=287
Issue 622: Update http_agent for Sguil 0.9 and move from SSL to TLS
https://code.google.com/p/security-onion/issues/detail?id=622
Issue 623: Update ossec_agent for Sguil 0.9 and move from SSL to TLS
https://code.google.com/p/security-onion/issues/detail?id=623
Issue 624: Update CapMe for Sguil 0.9 and move from SSL to TLS
https://code.google.com/p/security-onion/issues/detail?id=624
Issue 625: Update NSM for Sguil 0.9
https://code.google.com/p/security-onion/issues/detail?id=625
Issue 626: Update Setup for Sguil 0.9
https://code.google.com/p/security-onion/issues/detail?id=626
Issue 491: Squert 1.5.0
https://code.google.com/p/security-onion/issues/detail?id=491
Issue 638: securityonion-ossec-rules: add rule to ignore Squert POST
https://code.google.com/p/security-onion/issues/detail?id=638
Release Notes
Please note that the Squert interface has changed quite a bit from the previous version. In particular:
Updating
The new packages are now available in our stable repo. Please see the following page for full update instructions:
https://code.google.com/p/security-onion/wiki/Upgrade
Thanks
Thanks to the following for testing!
Eddy Simons
Mike Pilkington
Landon Lewis
David Zawdie
Feedback
If you have any questions or problems, please use our security-onion mailing list:
https://code.google.com/p/security-onion/wiki/MailingLists
Commercial Support
Need commercial support? Please see:
http://securityonionsolutions.com
Help Wanted
If you and/or your organization have found value in Security Onion, please consider giving back to the community by joining one of our teams:
https://code.google.com/p/security-onion/wiki/TeamMembers
We especially need help in answering support questions on the mailing list:
http://groups.google.com/group/security-onion
We also need help testing new packages:
http://groups.google.com/group/security-onion-testing
Thanks!
http://sourceforge.net/p/sguil/mailman/message/32230854/
http://www.squertproject.org/summaryofchangesforsquertversion130
http://www.squertproject.org/summaryofchangesforsquertversion140
http://www.squertproject.org/summaryofchangesforsquertversion150
I've updated our packages to include both of these releases. The new package versions are as follows:
securityonion-capme - 20121213-0ubuntu0securityonion20
securityonion-http-agent - 0.3.1-0ubuntu0securityonion6
securityonion-nsmnow-admin-scripts - 20120724-0ubuntu0securityonion88
securityonion-ossec-rules - 20120726-0ubuntu0securityonion4
securityonion-setup - 20120912-0ubuntu0securityonion125
securityonion-sguil-agent-ossec - 20120726-0ubuntu0securityonion4
securityonion-sguil-client - 20141004-0ubuntu0securityonion7
securityonion-sguil-sensor - 20141004-0ubuntu0securityonion7
securityonion-sguil-server - 20141004-0ubuntu0securityonion7
securityonion-squert - 20141015-0ubuntu0securityonion3
Issues Resolved
Issue 287: Sguil 0.9
https://code.google.com/p/security-onion/issues/detail?id=287
Issue 622: Update http_agent for Sguil 0.9 and move from SSL to TLS
https://code.google.com/p/security-onion/issues/detail?id=622
Issue 623: Update ossec_agent for Sguil 0.9 and move from SSL to TLS
https://code.google.com/p/security-onion/issues/detail?id=623
Issue 624: Update CapMe for Sguil 0.9 and move from SSL to TLS
https://code.google.com/p/security-onion/issues/detail?id=624
Issue 625: Update NSM for Sguil 0.9
https://code.google.com/p/security-onion/issues/detail?id=625
Issue 626: Update Setup for Sguil 0.9
https://code.google.com/p/security-onion/issues/detail?id=626
Issue 491: Squert 1.5.0
https://code.google.com/p/security-onion/issues/detail?id=491
Issue 638: securityonion-ossec-rules: add rule to ignore Squert POST
https://code.google.com/p/security-onion/issues/detail?id=638
Release Notes
Please note that the Squert interface has changed quite a bit from the previous version. In particular:
- To drill into an event to see the payload of the event, click on the value in the Status (ST) column.
- To generate a full pcap transcript, click on the value in the "Event ID" column.
Updating
The new packages are now available in our stable repo. Please see the following page for full update instructions:
https://code.google.com/p/security-onion/wiki/Upgrade
| Updating packages using "sudo soup" |
![]() |
| The new OSSEC rules package will prompt you to restart OSSEC |
![]() |
| The new securityonion-sguil-sensor package will prompt you to restart sensor services |
![]() |
| The new securityonion-sguil-server package will update your database and import your autocat rules |
![]() |
| The new securityonion-sguil-server package will then prompt you to restart server services |
![]() |
| The new securityonion-squert package will update your database |
![]() |
| Restarting OSSEC using "sudo service ossec-hids-server restart" |
![]() |
| Restarting server and sensor processes using "sudo service nsm restart" |
| The Sguil client is now updated to 0.9... |
![]() |
| ...and includes an AutoCat Rule Builder... |
![]() |
| ...and an AutoCat Viewer |
![]() |
| Squert has been updated to 1.5.0 |
![]() |
| Squert Event tab |
![]() |
| In Squert, you can now pivot to ELSA |
![]() |
| Pivoting from IP address in Squert to an ELSA query for the IP |
![]() |
| Squert now allows you to color code IP addresses |
![]() |
| Color-coded IP address |
![]() |
| Squert AutoCat Viewer |
![]() |
| Squert Summary tab including GeoIP mapping |
![]() |
| Squert Views tab with Sankey Diagram |
Thanks
Thanks to the following for testing!
Eddy Simons
Mike Pilkington
Landon Lewis
David Zawdie
Feedback
If you have any questions or problems, please use our security-onion mailing list:
https://code.google.com/p/security-onion/wiki/MailingLists
Commercial Support
Need commercial support? Please see:
http://securityonionsolutions.com
Help Wanted
If you and/or your organization have found value in Security Onion, please consider giving back to the community by joining one of our teams:
https://code.google.com/p/security-onion/wiki/TeamMembers
We especially need help in answering support questions on the mailing list:
http://groups.google.com/group/security-onion
We also need help testing new packages:
http://groups.google.com/group/security-onion-testing
Thanks!
Monday, October 6, 2014
OSSEC 2.8.1
OSSEC 2.8.1 was recently released:
http://www.ossec.net/?p=1135
Notice in the comments there is an additional patch which has now been applied to OSSEC on github:
https://github.com/ossec/ossec-hids/pull/315
I've packaged OSSEC 2.8.1 (with the patch from github) and also fixed a performance issue in our OSSEC configuration. Our OSSEC configuration now uses a new script called /usr/bin/sostat-interface to detect if an interface hasn't received any packets within a specific time interval (10 minutes by default).
The new package versions are as follows:
ossec-hids-server - 2.8.1-ubuntu10securityonion8
securityonion-sostat - 20120722-0ubuntu0securityonion31
The new packages have been tested by the following (thanks!):
David Zawdie
UPDATE 20141006 13:01
Scott F. found an issue in the postinst script:
https://groups.google.com/d/topic/security-onion/5LbonKad-88/discussion
This issue has been resolved and additional error handling has been added. The new package version is:
ossec-hids-server - 2.8.1-ubuntu10securityonion10
Issue 589: OSSEC 2.8.1
https://code.google.com/p/security-onion/issues/detail?id=589
Issue 621: sostat: add sostat-interface
https://code.google.com/p/security-onion/issues/detail?id=621
Updating
The new packages are now available in our stable repo. Please see the following page for full update instructions:
https://code.google.com/p/security-onion/wiki/Upgrade
After installing the new OSSEC package, you'll need to double-check /var/ossec/etc/ossec.conf and add back any local customizations. You can then restart OSSEC as follows:
Screenshots
Feedback
If you have any questions or problems, please use our security-onion mailing list:
https://code.google.com/p/security-onion/wiki/MailingLists
Training
Only 13 seats left for the 3-day Security Onion class in Richmond VA!
https://security-onion-class-20141020.eventbrite.com/
Commercial Support
Need commercial support? Please see:
http://securityonionsolutions.com
Help Wanted
If you and/or your organization have found value in Security Onion, please consider giving back to the community by joining one of our teams:
https://code.google.com/p/security-onion/wiki/TeamMembers
We especially need help in answering support questions on the mailing list:
http://groups.google.com/group/security-onion
We also need help testing new packages:
http://groups.google.com/group/security-onion-testing
Thanks!
http://www.ossec.net/?p=1135
Notice in the comments there is an additional patch which has now been applied to OSSEC on github:
https://github.com/ossec/ossec-hids/pull/315
I've packaged OSSEC 2.8.1 (with the patch from github) and also fixed a performance issue in our OSSEC configuration. Our OSSEC configuration now uses a new script called /usr/bin/sostat-interface to detect if an interface hasn't received any packets within a specific time interval (10 minutes by default).
The new package versions are as follows:
ossec-hids-server - 2.8.1-ubuntu10securityonion8
securityonion-sostat - 20120722-0ubuntu0securityonion31
The new packages have been tested by the following (thanks!):
David Zawdie
UPDATE 20141006 13:01
Scott F. found an issue in the postinst script:
https://groups.google.com/d/topic/security-onion/5LbonKad-88/discussion
This issue has been resolved and additional error handling has been added. The new package version is:
ossec-hids-server - 2.8.1-ubuntu10securityonion10
Issues Resolved
Issue 589: OSSEC 2.8.1
https://code.google.com/p/security-onion/issues/detail?id=589
Issue 621: sostat: add sostat-interface
https://code.google.com/p/security-onion/issues/detail?id=621
Updating
The new packages are now available in our stable repo. Please see the following page for full update instructions:
https://code.google.com/p/security-onion/wiki/Upgrade
After installing the new OSSEC package, you'll need to double-check /var/ossec/etc/ossec.conf and add back any local customizations. You can then restart OSSEC as follows:
sudo service ossec-hids-server restart
Screenshots
![]() |
| Update Process |
![]() |
| After updating, add back any local customization to ossec.conf and then run "sudo service ossec-hids-server restart" |
| OSSEC now runs /usr/bin/sostat-interface every 10 minutes to check for interfaces not receiving any traffic |
| When OSSEC sees that an interface hasn't received any packets, it alerts |
| OSSEC alert in Sguil |
![]() |
| sostat now reports on the number of packets received during the last monitoring interval |
Feedback
If you have any questions or problems, please use our security-onion mailing list:
https://code.google.com/p/security-onion/wiki/MailingLists
Training
Only 13 seats left for the 3-day Security Onion class in Richmond VA!
https://security-onion-class-20141020.eventbrite.com/
Commercial Support
Need commercial support? Please see:
http://securityonionsolutions.com
Help Wanted
If you and/or your organization have found value in Security Onion, please consider giving back to the community by joining one of our teams:
https://code.google.com/p/security-onion/wiki/TeamMembers
We especially need help in answering support questions on the mailing list:
http://groups.google.com/group/security-onion
We also need help testing new packages:
http://groups.google.com/group/security-onion-testing
Thanks!
Friday, September 12, 2014
New ossec-hids-server package resolves three issues
ossec-hids-server - 2.8.0-ubuntu10securityonion7 should resolve the following issues:
Issue 412: OSSEC 2.8
https://code.google.com/p/security-onion/issues/detail?id=412
Issue 573: OSSEC increase setmaxagents to 1024
https://code.google.com/p/security-onion/issues/detail?id=573
Issue 330: ossec.conf changes
https://code.google.com/p/security-onion/issues/detail?id=330
This new package has been tested by the following (thanks!):
Brian Kellogg
David Zawdie
Mike Seward
Installation Process
After installing the new OSSEC package, you'll need to double-check /var/ossec/etc/ossec.conf and add back any local customizations. Also, if you had added any local rules to /var/ossec/rules/local_rules.xml, you'll need to do the following:
You can then restart OSSEC as follows:
Updating
The new package is now available in our stable repo. Please see the following page for full update instructions:
https://code.google.com/p/security-onion/wiki/Upgrade
Feedback
If you have any questions or problems, please use our security-onion mailing list:
https://code.google.com/p/security-onion/wiki/MailingLists
Training
$400 off the new 3-day Security Onion class in Richmond VA!
http://blog.securityonion.net/2014/09/400-off-our-new-3-day-security-onion.html
Help Wanted
If you and/or your organization have found value in Security Onion, please consider giving back to the community by joining one of our teams:
https://code.google.com/p/security-onion/wiki/TeamMembers
We especially need help in answering support questions on the mailing list:
http://groups.google.com/group/security-onion
We also need help testing new packages:
http://groups.google.com/group/security-onion-testing
Thanks!
Issue 412: OSSEC 2.8
https://code.google.com/p/security-onion/issues/detail?id=412
Issue 573: OSSEC increase setmaxagents to 1024
https://code.google.com/p/security-onion/issues/detail?id=573
Issue 330: ossec.conf changes
https://code.google.com/p/security-onion/issues/detail?id=330
This new package has been tested by the following (thanks!):
Brian Kellogg
David Zawdie
Mike Seward
Installation Process
After installing the new OSSEC package, you'll need to double-check /var/ossec/etc/ossec.conf and add back any local customizations. Also, if you had added any local rules to /var/ossec/rules/local_rules.xml, you'll need to do the following:
sudo cp /var/ossec/rules/local_rules.xml-2.6 /var/ossec/rules/local_rules.xml
You can then restart OSSEC as follows:
sudo service ossec-hids-server restart
Updating
The new package is now available in our stable repo. Please see the following page for full update instructions:
https://code.google.com/p/security-onion/wiki/Upgrade
Feedback
If you have any questions or problems, please use our security-onion mailing list:
https://code.google.com/p/security-onion/wiki/MailingLists
Training
$400 off the new 3-day Security Onion class in Richmond VA!
http://blog.securityonion.net/2014/09/400-off-our-new-3-day-security-onion.html
Help Wanted
If you and/or your organization have found value in Security Onion, please consider giving back to the community by joining one of our teams:
https://code.google.com/p/security-onion/wiki/TeamMembers
We especially need help in answering support questions on the mailing list:
http://groups.google.com/group/security-onion
We also need help testing new packages:
http://groups.google.com/group/security-onion-testing
Thanks!
Tuesday, October 1, 2013
New Video on OSSEC and ELSA
I just published a quick video on OSSEC and ELSA. In this video, you'll see how quickly you can configure OSSEC and ELSA using Security Onion. We'll then use the ELSA web interface to hunt through OSSEC alerts and all logs received from all OSSEC agents. Also note that you can send standard syslog to ELSA and query those logs as well.
http://www.youtube.com/watch?v=xlRESlq86JI
Want to learn more about Log Management? Join me for SANS SEC434 Log Management In-Depth in Memphis TN on October 16th and 17th! This class is being held in conjunction with University of Memphis Center for Information Assurance Cyber Security Expo taking place October 18, 2013 at the FedEx Institute of Technology. Your paid tuition for this SANS course includes registration for the Cyber Security Expo when you register with Discount Code "ISC-Memphis":
http://www.sans.org/community/event/sec434-memphis-16oct2013-doug-burks
Want to learn more about Security Onion? Sign up for the upcoming 8-hour class in Augusta GA! Be one of the first 10 students to sign up and you can register at the discounted Early Bird price! For full details and to register, please see:
https://securityonion20131026.eventbrite.com/
http://www.youtube.com/watch?v=xlRESlq86JI
Want to learn more about Log Management? Join me for SANS SEC434 Log Management In-Depth in Memphis TN on October 16th and 17th! This class is being held in conjunction with University of Memphis Center for Information Assurance Cyber Security Expo taking place October 18, 2013 at the FedEx Institute of Technology. Your paid tuition for this SANS course includes registration for the Cyber Security Expo when you register with Discount Code "ISC-Memphis":
http://www.sans.org/community/event/sec434-memphis-16oct2013-doug-burks
Want to learn more about Security Onion? Sign up for the upcoming 8-hour class in Augusta GA! Be one of the first 10 students to sign up and you can register at the discounted Early Bird price! For full details and to register, please see:
https://securityonion20131026.eventbrite.com/
Monday, January 23, 2012
Security Onion 20120124 now available!
Security Onion 20120124 is now available! This resolves the following issue:
Issue 140: OSSEC agent needs to be integrated into NSM scripts
New Users
New users can download and install the 20111103 ISO image using the instructions here. The step marked "Install Security Onion updates" will automatically install this update.
In-place Upgrade
Existing Security Onion users can perform an in-place upgrade using the following command (if you're behind a proxy, remember to set your proxy variables as described in the FAQ):
sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh > ~/security-onion-upgrade.sh && bash ~/security-onion-upgrade.sh"
Screenshots
![]() |
| Upgrade Process |
![]() |
| sudo service nsm status |
If you have any questions, please join our mailing list and ask away!
http://groups.google.com/group/security-onion
Toolsmith Tool of the Year
If you're a fan of Security Onion, please vote for it for 2011 Toolsmith Tool of the Year!
http://holisticinfosec.blogspot.com/2011/12/choose-2011-toolsmith-tool-of-year.html
Thursday, November 17, 2011
Follow-up on OSSEC alerts for packet loss
This is a follow-up to my recent post "How do I receive an email when my sensor stops receiving traffic?". That post explains the core idea which I have since refined.
Refinement #1: Tell me which interface stopped receiving traffic
The first area of refinement is making the output a little more verbose so that, if we have multiple interfaces, we know exactly which interface stopped receiving traffic. We do that by modifying the "bandwidth" command in /var/ossec/etc/ossec.conf as follows:
<localfile>Refinement #2: Give me more flexibility in the OSSEC rule structure
<log_format>command</log_format>
<command>grep -v "^#" /etc/nsm/sensortab |awk '{print $1}' |while read SENSOR; do INTERFACE=`echo $SENSOR|cut -d\- -f3`; echo -n "$INTERFACE: "; tail -1 /nsm/sensor_data/$SENSOR/snort.st
ats |cut -d\, -f3; done</command>
<alias>bandwidth</alias>
</localfile>
The second area of refinement is implementing a tiered OSSEC rule structure. This gives us more flexibility and troubleshooting capability. We do this by editing /var/ossec/rules/local_rules.xml and replacing our previous single rule with these two rules:
<rule id="100001" level="1">
<if_sid>530</if_sid>
<match>ossec: output: 'bandwidth':</match>
<description>Bandwidth statistics from snort.stats</description>
</rule>
<rule id="100002" level="7">
<if_sid>100001</if_sid>
<regex>0.000</regex>
<description>Bandwidth down to 0.000. Please check interface, cabling, and tap/span!</description>
</rule>
The first rule just identifies "bandwidth" output and only logs it to disk (level 1 alerts do not generate email by default). The second rule is a child rule of the first and alerts/emails (level 7) when bandwidth is down to 0.000.
Since we're now logging all "bandwidth" output, we can search for it in the OSSEC logs:
grep "bandwidth" /var/ossec/logs/alerts/alerts.logRefinement #3: Use Linux kernel's built-in packet counters instead of relying on snort.stats
2011 Nov 17 14:28:50 so->bandwidth
ossec: output: 'bandwidth': eth4: 8.940
2011 Nov 17 14:28:50 so->bandwidth
ossec: output: 'bandwidth': eth5: 7.189
2011 Nov 17 14:38:54 so->bandwidth
ossec: output: 'bandwidth': eth4: 8.920
2011 Nov 17 14:38:54 so->bandwidth
ossec: output: 'bandwidth': eth5: 7.223
The third area of refinement is not relying on snort.stats but instead using the Linux kernel's built-in packet counters. (I hinted at this in the previous post.) This could be used to replace the entire "bandwidth" configuration above, or to complement it for a belt-and-suspenders approach. We start off by adding the following to /var/ossec/etc/ossec.conf:
<localfile>
<log_format>command</log_format>
<command>grep -v "^#" /etc/nsm/sensortab |awk '{print $4}' |while read SENSOR; do echo -n "$SENSOR: "; RX1=`ifconfig $SENSOR |awk '/RX packets/ {print $2}' |cut -d\: -f2`; sleep 300; RX2
=`ifconfig $SENSOR |awk '/RX packets/ {print $2}' |cut -d\: -f2`; expr $RX2 - $RX1; done</command>
<alias>packets_received</alias>
</localfile>
This follows the same format as the "bandwidth" command, but pulls the count of received packets from ifconfig, waits 5 minutes, pulls the RX count from ifconfig a second time, and subtracts the first from the second to get the total number of packets received in the 5-minute interval.
Next, we add these two rules to /var/ossec/rules/local_rules.xml:
<rule id="100003" level="1">
<if_sid>530</if_sid>
<match>ossec: output: 'packets_received':</match>
<description>Number of packets received in 5-minute interval</description>
</rule>
<rule id="100004" level="7">
<if_sid>100003</if_sid>
<regex> 0</regex>
<description>Received 0 packets in a 5-minute interval. Please check interface, cabling, and tap/span!</description>
</rule>
Since we're now logging all "packets_received" output, we can search for it in the OSSEC logs:
grep "packets_received" /var/ossec/logs/alerts/alerts.log
2011 Nov 17 14:33:50 so->packets_received
ossec: output: 'packets_received': eth4: 70969
2011 Nov 17 14:38:50 so->packets_received
ossec: output: 'packets_received': eth5: 63059
2011 Nov 17 14:43:54 so->packets_received
ossec: output: 'packets_received': eth4: 71030
2011 Nov 17 14:48:54 so->packets_received
ossec: output: 'packets_received': eth5: 67475
When the number of received packets drops to 0, rule 100004 triggers a level 7 alert, generating an email if configured to do so.
Wednesday, November 16, 2011
Security Onion 20111116 now available!
Security Onion 20111116 is now available! This resolves the following issue:
Issue 150 - Ensure that OSSEC timezone matches the host's timezone
New Users
New users can download and install the new 20111103 ISO image using the instructions here and then follow the In-Place Upgrade instructions below.
In-place Upgrade
Existing Security Onion users can perform an in-place upgrade using the following command (if you're behind a proxy, remember to set your proxy variables as described in the FAQ):
sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh > ~/security-onion-upgrade.sh && bash ~/security-onion-upgrade.sh"
Note that the upgrade script is cumulative and will upgrade any older version of Security Onion to the most recent version (including any updates in between).
Screenshots
![]() |
| Upgrade Process |
Tuesday, November 15, 2011
How do I receive an email when my sensor stops receiving traffic?
Recently, I logged into Sguil and noticed that a normally busy sensor had no current alerts. I looked at the full packet capture logs for the sensor and determined that it hadn't received any traffic from the tap in a while. We resolved the issue with the tap and started seeing traffic again, but I also resolved to create an automated notification for the next time this happens.
Snort is already writing bandwidth statistics to /nsm/sensor_data/$SENSOR/snort.stats and we are going to use OSSEC to monitor the file and send email when the bandwidth drops to 0. We could possibly write an OSSEC decoder to have it parse snort.stats directly, but let's instead use OSSEC's process monitoring feature so that we can perhaps extend this in the future to use the Linux kernel's built-in packet counters. For now, we're going to rely on snort.stats.
The first thing we need to do is obtain the full path to the snort.stats file(s) by determining the interfaces that are being monitored by Sguil. We do this by searching /etc/nsm/sensortab for any lines that are not commented out and piping to awk to print just the first column:
Security Onion has Snort's perfmonitor configured for 300-second intervals by default, which means that the value we're inspecting would be the average traffic for 5 minutes. My deployments have enough constant traffic that 0.000 for 5 minutes is a pretty good indicator of failure. YMMV!
Snort is already writing bandwidth statistics to /nsm/sensor_data/$SENSOR/snort.stats and we are going to use OSSEC to monitor the file and send email when the bandwidth drops to 0. We could possibly write an OSSEC decoder to have it parse snort.stats directly, but let's instead use OSSEC's process monitoring feature so that we can perhaps extend this in the future to use the Linux kernel's built-in packet counters. For now, we're going to rely on snort.stats.
The first thing we need to do is obtain the full path to the snort.stats file(s) by determining the interfaces that are being monitored by Sguil. We do this by searching /etc/nsm/sensortab for any lines that are not commented out and piping to awk to print just the first column:
grep -v "^#" /etc/nsm/sensortab |awk '{print $1}'
For each of the sensors in the output of the previous command, we want to look at the most recent bandwidth statistics, so we pipe to a while-loop and use "tail -1" on the respective snort.stats file:
grep -v "^#" /etc/nsm/sensortab |awk '{print $1}' |while read SENSOR; do tail -1 /nsm/sensor_data/$SENSOR/snort.stats; done
snort.stats is a CSV file and we only want the third column of data, so we pipe the previous command to cut and tell it the delimiter is a comma and to output the third field:
grep -v "^#" /etc/nsm/sensortab |awk '{print $1}' |while read SENSOR; do tail -1 /nsm/sensor_data/$SENSOR/snort.stats; done |cut -d\, -f3Here's some sample output for a sensor with two monitored interfaces:
3.481We now have a nice single command that OSSEC can run periodically to retrieve the bandwidth of our monitored interfaces. We add this as a "command" in /var/ossec/etc/ossec.conf and give it an alias of "bandwidth":
0.089
<localfile>
<log_format>command</log_format>
<command>grep -v "^#" /etc/nsm/sensortab |awk '{print $1}' |while read SENSOR; do tail -1 /nsm/sensor_data/$SENSOR/snort.stats; done |cut -d\, -f3</command>
<alias>bandwidth</alias>
</localfile>
Upon restart, OSSEC will periodically run the command, but won't do anything with the output until we add a rule to tell it what to do. We add the following rule to /var/ossec/rules/local_rules.xml to check the output hourly (every 3600 seconds) and see if the bandwidth value has gone down to 0.000:
<rule id="100001" level="7" ignore="3600">
<if_sid>530</if_sid>
<match>ossec: output: 'bandwidth':</match>
<regex>0.000</regex>
<description>Bandwidth down to 0.000. Please check interface, cabling, and tap/span!</description>
</rule>
If we didn't already have OSSEC configured to send email, we could do so by adding the following to the <global> section of /var/ossec/etc/ossec.conf:
<email_notification>yes</email_notification>
<email_to>YOUR.USERNAME@YOUR-DOMAIN.COM</email_to>
<smtp_server>YOUR-SMTP-RELAY.YOUR-DOMAIN.COM</smtp_server>
<email_from>OSSEC@YOUR-DOMAIN.COM</email_from>
Next, we restart OSSEC to activate the new configuration:
sudo service ossec restart
Finally, we simulate traffic loss and receive an email like the following:
OSSEC HIDS Notification.Update: A question over on Google+ prompted the following clarification:
2011 Nov 15 06:47:45
Received From: securityonion->bandwidth
Rule: 100001 fired (level 7) -> "Bandwidth down to 0.000. Please check interface, cabling, and tap/span!"
Portion of the log(s):
ossec: output: 'bandwidth': 0.000
Security Onion has Snort's perfmonitor configured for 300-second intervals by default, which means that the value we're inspecting would be the average traffic for 5 minutes. My deployments have enough constant traffic that 0.000 for 5 minutes is a pretty good indicator of failure. YMMV!
Wednesday, June 29, 2011
Security Onion 20110628 now available
Security Onion 20110628 is now available! This release fixes two minor issues with the OSSEC Sguil agent.
Existing Security Onion users can perform an in-place upgrade to version 20110628 using the following command (if you're behind a proxy, remember to set your proxy variables as described in the FAQ):
Existing Security Onion users can perform an in-place upgrade to version 20110628 using the following command (if you're behind a proxy, remember to set your proxy variables as described in the FAQ):
sudo -i "curl -L http://sourceforge.net/projects/security-onion/files/security-onion-upgrade.sh > ~/security-onion-upgrade.sh && bash ~/security-onion-upgrade.sh"
Subscribe to:
Posts (Atom)
Search This Blog
Featured Post
Registration Now Open for Augusta Cyber Week 2026!
Registration is now open for Augusta Cyber Week in beautiful Augusta GA from October 19, 2026 through October 24, 2026! This includes: 4-day...
Popular Posts
-
Security Onion 3.0.0 is now available and includes a new and improved interface, updated components, and many quality of life improvements! ...
-
Security Onion 2.4.180 is now available and includes several new features, updated components, and many quality of life improvements! For Se...
-
Security Onion 2.4.190 is now available and includes several new features, updated components, and many quality of life improvements! For S...
Blog Archive
- August 2026 (2)
- July 2026 (2)
- May 2026 (6)
- April 2026 (4)
- March 2026 (5)
- January 2026 (3)
- December 2025 (5)
- November 2025 (2)
- October 2025 (2)
- September 2025 (3)
- August 2025 (4)
- July 2025 (3)
- June 2025 (3)
- May 2025 (5)
- April 2025 (2)
- March 2025 (7)
- February 2025 (5)
- January 2025 (11)
- December 2024 (3)
- November 2024 (1)
- October 2024 (9)
- September 2024 (16)
- August 2024 (3)
- July 2024 (7)
- June 2024 (5)
- May 2024 (2)
- April 2024 (7)
- March 2024 (5)
- February 2024 (3)
- January 2024 (3)
- December 2023 (15)
- November 2023 (27)
- October 2023 (18)
- September 2023 (3)
- August 2023 (8)
- July 2023 (4)
- June 2023 (3)
- May 2023 (2)
- April 2023 (4)
- March 2023 (4)
- February 2023 (5)
- January 2023 (3)
- December 2022 (5)
- November 2022 (2)
- October 2022 (9)
- September 2022 (3)
- August 2022 (8)
- July 2022 (7)
- June 2022 (9)
- May 2022 (14)
- April 2022 (7)
- March 2022 (6)
- February 2022 (11)
- January 2022 (12)
- December 2021 (19)
- November 2021 (25)
- October 2021 (22)
- September 2021 (23)
- August 2021 (30)
- July 2021 (13)
- June 2021 (4)
- May 2021 (3)
- April 2021 (4)
- March 2021 (7)
- February 2021 (5)
- January 2021 (4)
- December 2020 (13)
- November 2020 (5)
- October 2020 (12)
- September 2020 (3)
- August 2020 (6)
- July 2020 (8)
- June 2020 (5)
- May 2020 (9)
- April 2020 (11)
- March 2020 (7)
- February 2020 (4)
- January 2020 (1)
- December 2019 (6)
- November 2019 (4)
- October 2019 (8)
- September 2019 (7)
- August 2019 (7)
- July 2019 (4)
- June 2019 (7)
- May 2019 (20)
- April 2019 (8)
- March 2019 (7)
- February 2019 (7)
- January 2019 (12)
- December 2018 (12)
- November 2018 (13)
- October 2018 (10)
- September 2018 (4)
- August 2018 (16)
- July 2018 (11)
- June 2018 (13)
- May 2018 (4)
- April 2018 (11)
- March 2018 (9)
- February 2018 (10)
- January 2018 (9)
- December 2017 (7)
- November 2017 (7)
- October 2017 (9)
- September 2017 (4)
- August 2017 (7)
- July 2017 (5)
- June 2017 (8)
- May 2017 (4)
- April 2017 (2)
- March 2017 (1)
- February 2017 (3)
- January 2017 (15)
- December 2016 (9)
- November 2016 (3)
- October 2016 (5)
- September 2016 (13)
- August 2016 (12)
- July 2016 (10)
- June 2016 (7)
- May 2016 (7)
- April 2016 (7)
- March 2016 (10)
- February 2016 (13)
- January 2016 (10)
- December 2015 (1)
- November 2015 (1)
- October 2015 (3)
- September 2015 (5)
- August 2015 (7)
- July 2015 (7)
- June 2015 (12)
- May 2015 (6)
- April 2015 (6)
- March 2015 (6)
- February 2015 (10)
- January 2015 (11)
- December 2014 (5)
- November 2014 (3)
- October 2014 (6)
- September 2014 (20)
- August 2014 (7)
- July 2014 (10)
- June 2014 (10)
- May 2014 (3)
- April 2014 (9)
- March 2014 (6)
- February 2014 (9)
- January 2014 (8)
- December 2013 (5)
- November 2013 (2)
- October 2013 (7)
- September 2013 (5)
- August 2013 (7)
- July 2013 (9)
- June 2013 (7)
- May 2013 (11)
- April 2013 (3)
- March 2013 (3)
- February 2013 (3)
- January 2013 (3)
- December 2012 (3)
- November 2012 (1)
- October 2012 (1)
- September 2012 (1)
- August 2012 (2)
- May 2012 (4)
- April 2012 (6)
- March 2012 (8)
- February 2012 (4)
- January 2012 (13)
- December 2011 (9)
- November 2011 (8)
- October 2011 (8)
- September 2011 (8)
- July 2011 (4)
- June 2011 (5)
- May 2011 (2)
- April 2011 (1)
- February 2011 (1)
- January 2011 (11)
- November 2010 (4)
- October 2010 (8)
- August 2010 (1)
- July 2010 (2)
- June 2010 (1)
- May 2010 (1)
- April 2010 (2)
- February 2010 (3)
- January 2010 (1)
- September 2009 (1)
- August 2009 (3)
- July 2009 (4)
- June 2009 (3)
- May 2009 (1)
- April 2009 (8)
- February 2009 (1)
- January 2009 (9)
- November 2008 (2)
- October 2008 (4)
- September 2008 (3)





























