logdata-anomaly-miner - 1.0.0-1 main

to analyze log data streams and detect violations or anomalies
in it. It can be run from console, as daemon with e-mail alerting
or embedded as library into own programs. It was designed to
run the analysis with limited resources and lowest possible permissions
to make it suitable for production server use. Analysis methods
include:
.
* static check patterns similar to logcheck but with extended
syntax and options.
* detection of new data elements (IPs, user names, MAC addresses)
* statistical anomalies in log line values and frequencies
* correlation rules between log lines as described in th AECID
approach http://dx.doi.org/10.1016/j.cose.2014.09.006
.
The tool is suitable to replace logcheck but also to operate
as a sensor feeding a SIEM.
.
Please report bugs at https://bugs.launchpad.net/logdata-anomaly-miner/+filebug

Priority: extra
Section: misc
Suites: amber byzantium crimson dawn landing 
Maintainer: Markus Wurzenberger <markus.wurzenberger [꩜] ait.ac.at>
 
Homepage Source Package
 

Dependencies

Installed Size: 479.2 kB
Architectures: all 

 

Versions

1.0.0-1 all