Hello Every one,
I want to setup a separate syslog server for all my cpanel servers to record all their activity there. Has any one done this before or if there is any tutorial available to do this ?
Any help would be appreciated.
Hello Every one,
I want to setup a separate syslog server for all my cpanel servers to record all their activity there. Has any one done this before or if there is any tutorial available to do this ?
Any help would be appreciated.
In my search i have found this : http://www.ossec.net/main/
Doe any one have any reviews about it ?
Can't help you but an interested in the same thing. Can I ask what made you look at ossec instead of something like kiwi syslog?
The reason coz i read about it at couple of places and also since it is backed by good company ..I have not yet made up my mind...
Have you implemented kiwi syslog ?
No, I was looking @ splunk but like you haven't made up my mind either. Was there a core feature of ossec that attracted you or were you more interested in security & ids over say fault finding and troubleshooting.
How did you see it integrating with cPanel hosts
Last edited by mobcdi; 06-15-2011 at 05:39 AM.
i have no idea yet...
The reason i posted on the board so that members here could suggest one ..
In fact i was looking for HOW-TO on this or any other log server...But in vein
any one ?
I can see it integrating several different ways. Obviously the fact that you can configure any rule to match any log entry you could easily say, disable accounts (or change passwords) of email accounts that are sending spam or large volumes of spam. Automatically setup firewall rules to block IPs of people who are behaving badly. Send notifications related to disk space or other important things that should be monitored. File integrity checking is important as well. I also see it as imperative to get PCIDSS compliant.
Of course there are plugins and other applications that can do several of these steps already, but I guess the PCIDSS compliance is my main reason for wanting to install OSSEC.
Pcidss ????
It would be PCI DSS compliant:
https://www.pcisecuritystandards.org...ity_standards/
cPResources: Support Options | More Support Options | Forums Search | cPanel.net Site Search | Mailing Lists(Alt) | Docs
-- Tristan, Forums Technical Analyst, cPanel Tech Support
Submit a ticket | Check an existing ticket