So, first things first .. while I was researching information for this post I very quickly realised that safesearch is a requirement! Who would have thought that outside of the NSM world people would be posting about this whole “squert” thing (and not in a very savoury fashion either!)
With that said, let’s move on to my next topic!
We’ve spent a couple of posts now using Security Onion to do some basic web application attack detection where we looked at an attack & wrote a basic rule to detect it. We then looked at using sguil for categorising events manually, using the autocat.conf file for automatically categorising events and configuring the sguild.conf file to generate an email alert when certain alerts were generated. Today we are going to look at using squert for monitoring and reporting. The basic web interface reports generated by squert are great for non-technical management (they always love pretty colours, bar graphs, pie charts etc.), but as an analyst you can also use the interface to drill down into the alerts to get far greater detail. This post will focus more on the types of reports that could be shown to management, or included in monthly reports and so on, as an analyst I would suspect you would much rather work in sguil (well, I would).




