0

I'm using OSSEC server to monitor machines with OSSEC agents, which monitor this login via SSH, file creation, etc.

I have configured OSSEC to send an email when it detects a problem, but this control mode is very bad for data control and search.

How can I analyze the logs like a dashboard, all log occurrences? Analyze by type of threat, date of occurrence, etc.

Tom
  • 217
  • 3
  • 12
  • Requests for product, service, or learning material recommendations are off-topic because they attract low quality, opinionated and spam answers, and the answers become obsolete quickly. Instead, describe the business problem you are working on, the research you have done, and the steps taken so far to solve it. – djdomi Apr 26 '22 at 16:50

0 Answers0