Irregular Expressions

Jul 22 2010   11:31AM GMT

Opensource Event Correlation System – Part 3

Dan O'Connor Dan O'Connor Profile: Dan O'Connor

Here is the rc file that I created for it.


# PROVIDE: sagan

. /etc/rc.subr


load_rc_config $name

: ${sagan_enable="NO"}


sagan_start() {
        chown sagan:sagan /var/log/sagan/log.fifo
        ${sagancmd} &

sagan_stop() {
        killall sagan

run_rc_command "$1"

Just make sure you enable the service in your /etc/rc.conf file, or you might have a problem 🙂

You can also start making your own rule sets and rules, the how-to has a good deal of information on this.  I created one already.

It was really quick and if you are used to created rules for snort it should not be a problem.

 Comment on this Post

There was an error processing your information. Please try again later.
Thanks. We'll let you know when a new response is added.
Send me notifications when other members comment.

Forgot Password

No problem! Submit your e-mail address below. We'll send you an e-mail containing your password.

Your password has been sent to:

Share this item with your network: