Irregular Expressions

Jul 22 2010   11:31AM GMT

Opensource Event Correlation System – Part 3

Dan O'Connor Dan O'Connor Profile: Dan O'Connor

Here is the rc file that I created for it.


# PROVIDE: sagan

. /etc/rc.subr


load_rc_config $name

: ${sagan_enable="NO"}


sagan_start() {
        chown sagan:sagan /var/log/sagan/log.fifo
        ${sagancmd} &

sagan_stop() {
        killall sagan

run_rc_command "$1"

Just make sure you enable the service in your /etc/rc.conf file, or you might have a problem 🙂

You can also start making your own rule sets and rules, the how-to has a good deal of information on this.  I created one already.

It was really quick and if you are used to created rules for snort it should not be a problem.

 Comment on this Post

There was an error processing your information. Please try again later.
Thanks. We'll let you know when a new response is added.
Send me notifications when other members comment.

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Forgot Password

No problem! Submit your e-mail address below. We'll send you an e-mail containing your password.

Your password has been sent to:

Share this item with your network: