sagan
Real-time System & Event Log Monitoring System
Install
- All systems
-
curl cmd.cat/sagan.sh
- Debian
-
apt-get install sagan
- Ubuntu
-
apt-get install sagan
- Kali Linux
-
apt-get install sagan
- Windows (WSL2)
-
sudo apt-get update
sudo apt-get install sagan
- Raspbian
-
apt-get install sagan
- Dockerfile
- dockerfile.run/sagan
sagan
Real-time System & Event Log Monitoring System
Sagan is a multi-threaded, real time system- and event-log monitoring system, but with a twist. Sagan uses a “Snort” like rule set for detecting malicious events happening on your network and/or computer systems. If Sagan detects a potentially bad event, that event can be stored to a Snort database (MySQL/PostgreSQL), send it to a SIEM tool like Prelude, or send an email. Sagan is meant to be used in a ‘centralized’ logging environment, but will work fine as part of a standalone Host IDS system for workstations.