Working NXLog Configuration File – OSSIM
Please find below the links to working configuration files used in the video titled “Overview of OSSIM Web Console – Installation of NXLog” Nxlog Configuration Fi
Sysmon Playbook Event ID 3
Sysmon Event ID: 3 Sysmon Event Title: Network Connection Detected Network Connection Attributes: When any machines with Sysmon installed makes a network connection many details ab
SYSMON Playbook – Event ID 1
Windows by default records most of the activity happening on OS in the Windows logs and can be viewed in Windows Event Viewer. However the Sysmon is much better when it comes to pr
Alien Vault Reconfiguration
Alienvault-reconfig creates the live configuration, loads the appropriate values, and makes sure all appropriate changes are made to dependent service configurations. Alienvault-re
Alien Vault Events Not Coming
Some of the options that can be pursued to troubleshoot and resolve this issue have been mentioned below: Login to Alien Vault server using putty with “root” credentials. After
Alien Vault TCPdump Troubleshoot
Some of the options that can be pursued to troubleshoot and resolve this issue have been mentioned below: Login to Alien Vault server using putty with “root” credentials. After
Alien Vault Configuration Backup
Backing up the configuration is one of the important thing that analyst should take care of. Since AlienVault configuration include system profile, network configuration, inventory
Alien Vault Update
If there is an update available from the Alien Vault please follow the below mentioned points. To check if there is an update available, go to your browser and type Alien Vault ser
Alarm Backup – AlienVault
Login via WinSCP to the Server. Go to this path:/var/alienvault/backup/ File name should be like: Configuration_CLIENT-AIO_1429616586.tar.gz Copy Alarm file to the local machine in
Alien Vault Alarms Not Recevied
For all MSSPs or users who are working with Alien Vault as a SIEM solution in their enterpise infrastructure it is common to get into problem because of alarms not being triggered