Bug 198741 - New port: security/sagan: Security tool to alert on log files
Summary: New port: security/sagan: Security tool to alert on log files
Status: Closed Overcome By Events
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Only Me
Assignee: Walter Schwarzenfeld
URL:
Keywords: needs-qa
Depends on:
Blocks:
 
Reported: 2015-03-20 15:30 UTC by shadowbq
Modified: 2018-03-05 19:28 UTC (History)
2 users (show)

See Also:


Attachments
Initial Shar file (5.43 KB, text/plain)
2015-03-20 15:30 UTC, shadowbq
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description shadowbq 2015-03-20 15:30:22 UTC
Created attachment 154580 [details]
Initial Shar file

Sagan uses a 'Snort like' engine and rules to analyze logs.

Sagan is an open source (GNU/GPLv2) high performance, real-time log
analysis & correlation engine.  It is written in C and uses a
multi-threaded architecture to deliver high performance log & event
analysis.

The Sagan structure and Sagan rules work similarly to the
Sourcefire "Snort" IDS engine. This was intentionally done to maintain
compatibility with rule management software (oinkmaster/pulledpork/etc)
and allows Sagan to correlate log events with your Snort IDS/IPS
system. Since Sagan can write to Snort IDS/IPS databases via
unified2/barnyard2, it is compatible with all Snort "consoles".
For example, Sagan is compatible with Snorby [http://www.snorby.org],
Sguil [http://sguil.sourceforge.net], BASE, and the Prelude IDS
framework! (to name a few).

For more information, please visit the Sagan web site:
WWW: http://sagan.quadrantsec.com.
Comment 1 Carlo Strub freebsd_committer freebsd_triage 2015-09-15 23:46:06 UTC
Could you please provide build logs (preferably poudriere logs).
Comment 2 Walter Schwarzenfeld freebsd_triage 2018-01-14 04:26:06 UTC
Last statement from 2015-03-20. Feedback timeout?
Comment 3 Walter Schwarzenfeld freebsd_triage 2018-03-05 19:28:29 UTC
The Makefile is outdated with deprecated commands. Does not fetch. Feedback timeout. I close here with overcome by events.

If you want submit the port in a newer version, please open a new PR.