Irregular Expressions

Jul 22 2010   11:31AM GMT

Opensource Event Correlation System – Part 3

Dan O'Connor Dan O'Connor Profile: Dan O'Connor

Here is the rc file that I created for it.

#!/bin/sh

# PROVIDE: sagan
#

. /etc/rc.subr

name="sagan"
rcvar=${name}_enable

load_rc_config $name

: ${sagan_enable="NO"}

start_cmd=${name}_start
stop_cmd=${name}_stop
sagancmd="/usr/local/bin/sagan"

sagan_start() {
        chown sagan:sagan /var/log/sagan/log.fifo
        ${sagancmd} &
}

sagan_stop() {
        killall sagan
}

run_rc_command "$1"

Just make sure you enable the service in your /etc/rc.conf file, or you might have a problem 🙂

You can also start making your own rule sets and rules, the how-to has a good deal of information on this.  I created one already.

It was really quick and if you are used to created rules for snort it should not be a problem.

 Comment on this Post

 
There was an error processing your information. Please try again later.
Thanks. We'll let you know when a new response is added.
Send me notifications when other members comment.

Forgot Password

No problem! Submit your e-mail address below. We'll send you an e-mail containing your password.

Your password has been sent to:

Share this item with your network: