Reporting

372 views
Skip to first unread message

Simon

unread,
Jul 25, 2013, 6:36:08 AM7/25/13
to securit...@googlegroups.com
What is the best way to generate reports for events? I have used Snorby to generate a report but I could really do with a way to customise reports for instance generate a report for a specific sensor or network range.

Any suggestions?


Many Thanks


Simon

Heine Lysemose

unread,
Jul 25, 2013, 7:31:22 AM7/25/13
to securit...@googlegroups.com
Hi Simon

Sguil has some capabilities to report. I haven't done this myself but I see the menu from the client.

Otherwise, I know it isn't report, but ELSA has a dashboard functionality, 

Here are two dashbaords for Snort and Bro

At last you can always query the database yourself.

Regards,
Lysemose





Simon

--
You received this message because you are subscribed to the Google Groups "security-onion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-onio...@googlegroups.com.
To post to this group, send email to securit...@googlegroups.com.
Visit this group at http://groups.google.com/group/security-onion.
For more options, visit https://groups.google.com/groups/opt_out.



Simon

unread,
Jul 25, 2013, 8:33:15 AM7/25/13
to securit...@googlegroups.com
Yea some reason SGUIL just seems to generate an empty report for which ever sensor I choose, ideally I would like a report like Snorbys but with the ability to select exactly what you want in it. I might end up having to manually create a report probably using Squerts data.

Thanks

Simon

Martin Holste

unread,
Jul 25, 2013, 6:32:46 PM7/25/13
to security-onion
You can schedule ELSA queries as reports.  They can run against indexed or archived data.  What kinds of event reporting are you interested in?

Simon Hall

unread,
Jul 31, 2013, 4:56:49 PM7/31/13
to securit...@googlegroups.com
Sorry for the delay I have been away for a week, how do you go about scheduling ELSA queries as reports, I would like to generate a Report for all events on a specific network, maybe with TOP source and destination data.


--
You received this message because you are subscribed to a topic in the Google Groups "security-onion" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/security-onion/p5TG9-84am8/unsubscribe.
To unsubscribe from this group and all its topics, send an email to security-onio...@googlegroups.com.

Martin Holste

unread,
Aug 2, 2013, 10:10:32 PM8/2/13
to security-onion
Once you get the query you like, click "Alert or schedule" under the "Result Options" button.  You can then schedule that query to be run any schedule you like.
Reply all
Reply to author
Forward
0 new messages