Sagan (software)

From Wikipedia, the free encyclopedia

This is an old revision of this page, as edited by 173.165.207.27 (talk) at 19:27, 23 May 2020 (→‎References). The present address (URL) is a permanent link to this revision, which may differ significantly from the current revision.

Original author(s)Champ Clark III
Developer(s)Quadrant Information Security
Stable release
1.2.2 / 3 July 2019; 4 years ago (2019-07-03)
Written inC
Operating systemUnix-like
Available inEnglish
TypeLog analysis
LicenseGNU GPL v2
Websitequadrantsec.com/sagan_log_analysis_engine

Sagan[1] is an open source (GNU/GPLv2) multi-threaded, high performance, real-time log analysis & correlation engine developed by Quadrant Information Security that runs on Unix operating systems. It is written in C and uses a multi-threaded architecture to deliver high performance log & event analysis. Sagan's structure and rules work similarly to the Sourcefire Snort IDS/IPS engine. This allows Sagan to be compatible with Snort or Suricata rule management softwares and give Sagan the ability to correlate with Snort IDS/IPS data. Sagan can record events to the Snort "unified2" output format which makes Sagan compatible with user interfaces such as Snorby, Sguil, BASE and proprietary consoles

Sagan supports different output formats for reporting and analysis, log normalization, script execution on event detection, automatic firewall support via "Snortsam", GeoIP detection/alerting, multi-line log support, and time sensitive alerting.

See also

References

  1. ^ "Sagan Main Wiki". Sagan Main Wiki. Champ Clark.

External links