Welcome to the Prelude Universal Open-Source SIEM project¶
We just upgrade the Prelude OSS VA to 4.1 here
Prelude is a Universal "Security Information & Event Management" (SIEM) system. Prelude collects, normalizes, sorts, aggregates, correlates and reports all security-related events independently of the product brand or license giving rise to such events; Prelude is "agentless".
As well as being capable of recovering any type of log (system logs, syslog, flat files, etc.), Prelude benefits from a native support with a number of systems dedicated to enriching information even further (snort, samhain, ossec, auditd, etc.).Actual Linux distributions support:
- Fedora/RedHat/CentOS(epel): Prelude OSS 4.1
- Debian/Ubuntu: Prelude OSS 4.1
- Gentoo: Prelude OSS 4.1
- Mageia: Prelude OSS 4.1
- Arch Linux: Prelude OSS 4.1
- OpenSuse: Prelude OSS 4.0 (Update to 4.1 in progress)
- Auditd (Homepage)
- ufwi-filterd (Homepage)
- OSSEC (Homepage)
- Snort (Homepage)
- Suricata (Homepage)
- Kismet (Homepage)
- ClamAV (Homepage)
- Waiting for approval:
Security events are normalized thanks to a single format, called the "Intrusion Detection Message Exchange Format" (IDMEF - RFC4765), which is an international standard created upon the initiative of IETF along with the participation of Prelude teams to enable interacting with the various security tools currently available on the market.
WARNING on Prelude OSS Edition Vs Prelude SIEM Edition¶
Prelude OSS is the open source edition of Prelude SIEM . Prelude OSS is aimed for evaluation, research and test purpose on very small environments. Please note that Prelude OSS performances are way lower than the Prelude SIEM edition.
Prelude Documentation Sections¶
- Prelude Download Page
- Repository Access
- Prelude Project
- Prelude-SIEM Company Home Page
- Prelude Specifications
The Prelude Team.