Hello Team,
Is there is possibility to export logs from Nagios Log Server to any other tool? for example SIEM [Security information and event management] tool.
Regards,
Swapnil
Can we export logs to SIEM System
-
scottwilkerson
- DevOps Engineer
- Posts: 19396
- Joined: Tue Nov 15, 2011 3:11 pm
- Location: Nagios Enterprises
- Contact:
Re: Can we export logs to SIEM System
Not sure what system you are trying to connect to, but I will say that you can output logs data to additional locations, that could be another system, seperate log files, pass them through a script etc.
You can find this under Administration -> Global Configuration -> Show Output's button
You can find this under Administration -> Global Configuration -> Show Output's button
Re: Can we export logs to SIEM System
We use RSA’s Security Analytics for the SIEM system which is located at different site, and would like to forward the logs from Nagios Log Server to this system? Is it possible?
Re: Can we export logs to SIEM System
Using the output method that Scott mentioned in the previous post, it is likely possible.
Take a look at this page: https://www.elastic.co/guide/en/logstas ... ugins.html
Take a look at this page: https://www.elastic.co/guide/en/logstas ... ugins.html
Former Nagios Employee.
me.
me.
Re: Can we export logs to SIEM System
Is there a Nagios Documentation for using additional output locations? or scripts?
Re: Can we export logs to SIEM System
To hijack this thread for a minute, I'd love an "Export to Text" button on the "all events" list. We've got a file output filter to put things into a folder structure, but it would be really nice to be able to do a quick export of what's on the screen, without having to potentially correlate multiple output files.
Eric Loyd • http://everwatch.global • 844.240.EVER • @EricLoyd
I'm a Nagios Fanatic! • Join our public Nagios Discord Server!
Re: Can we export logs to SIEM System
A similar feature request has existed for awhile. We're aware of the demand for this feature.eloyd wrote:To hijack this thread for a minute, I'd love an "Export to Text" button on the "all events" list. We've got a file output filter to put things into a folder structure, but it would be really nice to be able to do a quick export of what's on the screen, without having to potentially correlate multiple output files.
There is not currently. Generally the documentation provided by Elastic can give good information about what you're trying to do. Our goal is for NLS to be the end point for your logs, so there's never been a giant demand to forward them to other logging solutions.sgiworks wrote:Is there a Nagios Documentation for using additional output locations? or scripts?
Former Nagios Employee.
me.
me.
Re: Can we export logs to SIEM System
I get that, but once you've spent time sorting, filtering, querying, and specifying time stamps, the resulting data set is often exactly what you need to export to put into a security response report. Meaning, it's MUCH easier to get this information from NLS than it is from the source logs.
I'll wait patiently for a new release.
I'll wait patiently for a new release.
Eric Loyd • http://everwatch.global • 844.240.EVER • @EricLoyd
I'm a Nagios Fanatic! • Join our public Nagios Discord Server!
Re: Can we export logs to SIEM System
We recently did an intrusion detection and analysis using nothing but NLS and NNA that went above and beyond what the customer's existing, highly paid network consultants could do. Being able to export NLS logs as text/PDF would have been awesome.
Eric Loyd • http://everwatch.global • 844.240.EVER • @EricLoyd
I'm a Nagios Fanatic! • Join our public Nagios Discord Server!