Pakket: logdata-anomaly-miner (1.0.0-1)
Verwijzigingen voor logdata-anomaly-miner
Debian bronnen:
Het bronpakket logdata-anomaly-miner downloaden:
- [logdata-anomaly-miner_1.0.0-1.dsc]
- [logdata-anomaly-miner_1.0.0.orig.tar.gz]
- [logdata-anomaly-miner_1.0.0.orig.tar.gz.asc]
- [logdata-anomaly-miner_1.0.0-1.debian.tar.xz]
Beheerder:
Externe bronnen:
- Homepage [launchpad.net]
Vergelijkbare pakketten:
This tool allows one to create log analysis pipelines
to analyze log data streams and detect violations or anomalies in it. It can be run from console, as daemon with e-mail alerting or embedded as library into own programs. It was designed to run the analysis with limited resources and lowest possible permissions to make it suitable for production server use. Analysis methods include:
* static check patterns similar to logcheck but with extended syntax and options. * detection of new data elements (IPs, user names, MAC addresses) * statistical anomalies in log line values and frequencies * correlation rules between log lines as described in th AECID approach http://dx.doi.org/10.1016/j.cose.2014.09.006
The tool is suitable to replace logcheck but also to operate as a sensor feeding a SIEM.
Please report bugs at https://bugs.launchpad.net/logdata-anomaly-miner/ filebug
Andere aan logdata-anomaly-miner gerelateerde pakketten
|
|
|
|
-
- dep: python3
- interactive high-level object-oriented language (default python3 version)
-
- dep: python3-tz
- Python3 version of the Olson timezone database
-
- sug: python-scipy
- scientific tools for Python