Misplaced Pages

Sagan (software)

Article snapshot taken from Wikipedia with creative commons attribution-sharealike license. Give it a read and then ask your questions in the chat. We can research this topic together.
Log analysis software
This article needs additional citations for verification. Please help improve this article by adding citations to reliable sources. Unsourced material may be challenged and removed.
Find sources: "Sagan" software – news · newspapers · books · scholar · JSTOR (October 2014) (Learn how and when to remove this message)
This article includes a list of references, related reading, or external links, but its sources remain unclear because it lacks inline citations. Please help improve this article by introducing more precise citations. (July 2024) (Learn how and when to remove this message)
Original author(s)Champ Clark III
Developer(s)Quadrant Information Security
Stable release2.0.1 / 8 February 2021; 3 years ago (2021-02-08)
Written inC
Operating systemUnix-like
Available inEnglish
TypeLog analysis
LicenseGNU GPL v2
Websitequadrantsec.com/sagan_log_analysis_engine

Sagan is an open source (GNU/GPLv2) multi-threaded, high performance, real-time log analysis & correlation engine developed by Quadrant Information Security that runs on Unix operating systems. It is written in C and uses a multi-threaded architecture to deliver high performance log & event analysis. Sagan's structure and rules work similarly to the Sourcefire Snort IDS/IPS engine. This allows Sagan to be compatible with Snort or Suricata rule management software and gives Sagan the ability to correlate with Snort IDS/IPS data.

Sagan supports different output formats for reporting and analysis, log normalization, script execution on event detection, GeoIP detection/alerting and time sensitive alerting.

See also

References

  1. "Sagan Main Wiki". Sagan Main Wiki. Champ Clark.

External links

Categories: