Questions tagged [alienvault]

8 questions
1
vote
1 answer

logs from snoopy in AlienVault/Ossim

I try to analyze logs from snoopy. For example: Dec 2 07:58:31 local.server snoopy[14165]: [uid:1660 sid:14056 tty:/dev/pts/1 cwd:/home/myuser filename:/usr/bin/ssh]: ssh root@remote.server I wrote a decoder:
fok
  • 11
  • 3
0
votes
1 answer

How do we install Alienvault's OSSIM in AWS?

Is there any process to install Alienvault's OSSIM in AWS apart from importing VM to AWS?
0
votes
0 answers

Issues with posting data to MongoDB via taxii server (medallion)

I am using medallion implementation of taxii (https://github.com/oasis-open/cti-taxii-server) to connect with OTX (https://github.com/AlienVault-OTX/OTX-Apps-TAXII). However, I seem to be getting this error on the taxii server. 127.0.0.1 - -…
0
votes
1 answer

Integrate TAXII Feed from Alienvault OTX into IBM Qradar

I am currently trying to integrate the TAXII Feed provided by Alienvault OTX into QRadar. Now I have the problem that no "items" are retrieved from the TAXII server. The setup is "working", I followed the instructions described in this link:…
SimmensK
  • 17
  • 7
0
votes
2 answers

NXlog will not start - AlienVault Config

I am trying to configure NXlog to work with AlienVault based on the guide here I installed the custom config file from AlienVault and modified the destination IP only. When I did this I could not get the NXlog service to start - Then I reinstalled…
Joe
  • 2,641
  • 5
  • 22
  • 43
0
votes
1 answer

How to detect a couple of pings transmitted from a virtual machine to another by using Snort, which is integrated in AlienVault?

For the record: I did the following instruction (found them on a website) I enabled snort sensors (snort_syslog and snortunified). In alienvault: ~# nano /etc/snort/rules/local.rules I did the following rule alert icmp 192.168.1.130 192.168.1.120…
0
votes
2 answers

Setting up OSSIM in a cloud environment

I am trying to setup OSSIM from Alientvault, via an ISO in my cloud instance. I have got the installation working in my local Virtual Box, however I can not get it to work on my cloud server. I have a vultr.com cloud server and have downloaded the…
IndikaM
  • 409
  • 7
  • 14
-2
votes
1 answer

Span Port Traffic From Host Os(CentOS) to Client VM in VirtualBox (USM)

I'm deploying Aienvault USM in VBox. Everything has worked fine until the network monitoring part where I should monitor SPAN Port traffic. From my host PC, I can see the traffic cmming in well on that specific port (eno4), I have bridged the same…
ShadrackD
  • 1
  • 1