Questions tagged [alienvault]
8 questions
1
vote
1 answer
logs from snoopy in AlienVault/Ossim
I try to analyze logs from snoopy.
For example:
Dec 2 07:58:31 local.server snoopy[14165]: [uid:1660 sid:14056 tty:/dev/pts/1 cwd:/home/myuser filename:/usr/bin/ssh]: ssh root@remote.server
I wrote a decoder:
…

fok
- 11
- 3
0
votes
1 answer
How do we install Alienvault's OSSIM in AWS?
Is there any process to install Alienvault's OSSIM in AWS apart from importing VM to AWS?

Ritesh Kumar Reddy Kuchukulla
- 402
- 3
- 11
0
votes
0 answers
Issues with posting data to MongoDB via taxii server (medallion)
I am using medallion implementation of taxii (https://github.com/oasis-open/cti-taxii-server) to connect with OTX (https://github.com/AlienVault-OTX/OTX-Apps-TAXII). However, I seem to be getting this error on the taxii server.
127.0.0.1 - -…

chanel potato
- 1
- 1
0
votes
1 answer
Integrate TAXII Feed from Alienvault OTX into IBM Qradar
I am currently trying to integrate the TAXII Feed provided by Alienvault OTX into QRadar. Now I have the problem that no "items" are retrieved from the TAXII server. The setup is "working", I followed the instructions described in this link:…

SimmensK
- 17
- 7
0
votes
2 answers
NXlog will not start - AlienVault Config
I am trying to configure NXlog to work with AlienVault based on the guide here
I installed the custom config file from AlienVault and modified the destination IP only. When I did this I could not get the NXlog service to start - Then I reinstalled…

Joe
- 2,641
- 5
- 22
- 43
0
votes
1 answer
How to detect a couple of pings transmitted from a virtual machine to another by using Snort, which is integrated in AlienVault?
For the record: I did the following instruction (found them on a website)
I enabled snort sensors (snort_syslog and snortunified).
In alienvault: ~# nano /etc/snort/rules/local.rules
I did the following rule
alert icmp 192.168.1.130 192.168.1.120…

Radulian Defta
- 1
- 1
0
votes
2 answers
Setting up OSSIM in a cloud environment
I am trying to setup OSSIM from Alientvault, via an ISO in my cloud instance.
I have got the installation working in my local Virtual Box, however I can not get it to work on my cloud server.
I have a vultr.com cloud server and have downloaded the…

IndikaM
- 409
- 7
- 14
-2
votes
1 answer
Span Port Traffic From Host Os(CentOS) to Client VM in VirtualBox (USM)
I'm deploying Aienvault USM in VBox. Everything has worked fine until the network monitoring part where I should monitor SPAN Port traffic.
From my host PC, I can see the traffic cmming in well on that specific port (eno4), I have bridged the same…

ShadrackD
- 1
- 1