Open Source SIM Installation with Prelude

Comments

2 comments posted
Have you tried out OSSIM?

Hi,

Without knowing better, have you tried out OSSIM?
I'm thinking about using that as a frontend to snort and ossec.

But haven't started the project yet..
So perhaps it is too much...

--
Regards Falk

Posted by Anonymous on Wed, 2009-12-23 14:00
Re: Have you tried out OSSIM?

Falk,

Yes, in addition to Prelude I also looked at OSSIM and Sguil for the GUI. I personally found OSSIM too complex and more focused on visual appeal than usability. For example, in addition to being a SIEM, OSSIM includes a ticketing system, network performance monitoring, system inventory, vulnerability scanner, and more. All of them together create pretty executive dashboards and graphs, but I'd didn't find it very useful to manage tactical security event information.

Squil would be a good alternative but is more NIDS focused and hasn't been updated in over a year. Although I don't mind that it's written in TCL directly, it isn't a language that I'm very familiar with, which was also a downside for me.

Further, Prelude's use of IDMEF also helps it integrate well with OSSEC and Snort. Although IDMEF may be a failed standard, it provides good integration by providing a standard format for the data.

I would encourage you to try both Prelude and OSSIM in a lab to decide for yourself. Personally, I found Prelude much more usable for my needs, although it lacks the bells and whistles that OSSIM has.

- Christopher

Posted by Christopher on Thu, 2009-12-24 13:15