Monday, February 2, 2009

OSSEC and Splunk

Here's how I configured OSSEC to send alerts to Splunk:

In ossec.conf add a syslog_output block specifying your Splunk system IP address and the port your network input is listening on:


Now you need to enable the syslog_output module and restart OSSEC:

#/var/ossec/bin/ossec-control enable client-syslog
#/var/ossec/bin/ossec-control restart

On restart you'll see ossec-csyslogd starting up. Now for the Splunk side.

You have a few options on how to receive OSSEC alerts. The two options I've looked at are a standard Splunk network input or syslog-ng. I would suggest using syslog-ng and either the FIFO or file destination method. This way when you need to restart Splunk, which can be rather frequent, you won't lose events like you would with the Splunk network input. Here, for simplicity I'll just walk through the Splunk network input method.

The easiest method is by adding this stanza to inputs.conf:


[udp://] #IP address of OSSEC server
disabled = false
sourcetype = ossec

By setting the sourcetype as OSSEC you're ready to take advantage of the Splunk for OSSEC app which will be available at Splunkbase shortly (

Make sure you update any local or network firewalls that this communication is traversing and then restart Splunk.

#$SPLUNK_HOME/bin/splunk restart

You can accomplish this using Splunk Web or Splunk CLI as documented here:

If you have any tweaks or improvements to configuration or the Splunk for OSSEC app please let me know!


Ann said...

COACH is a well-known brand Coach Outlet,Coach has all kinds of handbag designs Coach Handbags,All of these kind of Coach totes,The bow tie was find from ralph lauren polo, This offer has no cash value ralph lauren outlet,There are also various types polo ralph lauren,The pocket is usually slanted lacoste polo,The signature of crocodile is Moncler jackets,This is of classic fit Moncler,As we supply great A quality Moncler coats,We thank you for your attention gold ghd,this was worn by ED Hardy,who work in japan. its original Discount ED Hardy,all the shoes from us ED Hardy Outlet

Nasreen Basu said...

we are offering best splunk online training with job support and high quality training facilities and well expert faculty . to Register you free demo please visit ,splunk training in hyderabad

vignes waran said...

This blog explains the details about what happened after the expressions. This gives the details of the thinking next what to do.
Angularjs Training
Angularjs Online Training

nasreen basu said...

really cool post, highly informative and professionally written and I am glad to be a visitor of this perfect blog, thank you for this rare info!
splunk training in hyderabad
servicenow training in hyderabad