Can we export logs to SIEM System

This support forum board is for support questions relating to Nagios Log Server, our solution for managing and monitoring critical log data.
sgiworks
Posts: 197
Joined: Mon Mar 21, 2016 11:38 am

Can we export logs to SIEM System

Post by sgiworks »

Hello Team,

Is there is possibility to export logs from Nagios Log Server to any other tool? for example SIEM [Security information and event management] tool.

Regards,
Swapnil
scottwilkerson
DevOps Engineer
Posts: 19396
Joined: Tue Nov 15, 2011 3:11 pm
Location: Nagios Enterprises
Contact:

Re: Can we export logs to SIEM System

Post by scottwilkerson »

Not sure what system you are trying to connect to, but I will say that you can output logs data to additional locations, that could be another system, seperate log files, pass them through a script etc.

You can find this under Administration -> Global Configuration -> Show Output's button
Former Nagios employee
Creator:
Human Design Website
Get Your Human Design Chart
sgiworks
Posts: 197
Joined: Mon Mar 21, 2016 11:38 am

Re: Can we export logs to SIEM System

Post by sgiworks »

We use RSA’s Security Analytics for the SIEM system which is located at different site, and would like to forward the logs from Nagios Log Server to this system? Is it possible?
User avatar
hsmith
Agent Smith
Posts: 3539
Joined: Thu Jul 30, 2015 11:09 am
Location: 127.0.0.1
Contact:

Re: Can we export logs to SIEM System

Post by hsmith »

Using the output method that Scott mentioned in the previous post, it is likely possible.

Take a look at this page: https://www.elastic.co/guide/en/logstas ... ugins.html
Former Nagios Employee.
me.
sgiworks
Posts: 197
Joined: Mon Mar 21, 2016 11:38 am

Re: Can we export logs to SIEM System

Post by sgiworks »

Is there a Nagios Documentation for using additional output locations? or scripts?
User avatar
eloyd
Cool Title Here
Posts: 2190
Joined: Thu Sep 27, 2012 9:14 am
Location: Rochester, NY
Contact:

Re: Can we export logs to SIEM System

Post by eloyd »

To hijack this thread for a minute, I'd love an "Export to Text" button on the "all events" list. We've got a file output filter to put things into a folder structure, but it would be really nice to be able to do a quick export of what's on the screen, without having to potentially correlate multiple output files.
Image
Eric Loyd • http://everwatch.global • 844.240.EVER • @EricLoyd
I'm a Nagios Fanatic! • Join our public Nagios Discord Server!
User avatar
hsmith
Agent Smith
Posts: 3539
Joined: Thu Jul 30, 2015 11:09 am
Location: 127.0.0.1
Contact:

Re: Can we export logs to SIEM System

Post by hsmith »

eloyd wrote:To hijack this thread for a minute, I'd love an "Export to Text" button on the "all events" list. We've got a file output filter to put things into a folder structure, but it would be really nice to be able to do a quick export of what's on the screen, without having to potentially correlate multiple output files.
A similar feature request has existed for awhile. We're aware of the demand for this feature.
sgiworks wrote:Is there a Nagios Documentation for using additional output locations? or scripts?
There is not currently. Generally the documentation provided by Elastic can give good information about what you're trying to do. Our goal is for NLS to be the end point for your logs, so there's never been a giant demand to forward them to other logging solutions.
Former Nagios Employee.
me.
User avatar
eloyd
Cool Title Here
Posts: 2190
Joined: Thu Sep 27, 2012 9:14 am
Location: Rochester, NY
Contact:

Re: Can we export logs to SIEM System

Post by eloyd »

I get that, but once you've spent time sorting, filtering, querying, and specifying time stamps, the resulting data set is often exactly what you need to export to put into a security response report. Meaning, it's MUCH easier to get this information from NLS than it is from the source logs.

I'll wait patiently for a new release. :-)
Image
Eric Loyd • http://everwatch.global • 844.240.EVER • @EricLoyd
I'm a Nagios Fanatic! • Join our public Nagios Discord Server!
User avatar
hsmith
Agent Smith
Posts: 3539
Joined: Thu Jul 30, 2015 11:09 am
Location: 127.0.0.1
Contact:

Re: Can we export logs to SIEM System

Post by hsmith »

I don't disagree. :)
Former Nagios Employee.
me.
User avatar
eloyd
Cool Title Here
Posts: 2190
Joined: Thu Sep 27, 2012 9:14 am
Location: Rochester, NY
Contact:

Re: Can we export logs to SIEM System

Post by eloyd »

We recently did an intrusion detection and analysis using nothing but NLS and NNA that went above and beyond what the customer's existing, highly paid network consultants could do. Being able to export NLS logs as text/PDF would have been awesome.
Image
Eric Loyd • http://everwatch.global • 844.240.EVER • @EricLoyd
I'm a Nagios Fanatic! • Join our public Nagios Discord Server!
Locked