Operating System - HP-UX
1832978 Members
2617 Online
110048 Solutions
New Discussion

HIDS client other than HP-UX

 
Derek Whigham_1
Trusted Contributor

HIDS client other than HP-UX

I am using HIDS v4 on a large HP-UX network(55 Servers) I also have Solaris, Linux and Windows Servers , Is there a client available for the OS's that will talk to HIDS or it there a way to forward syslog(ng) events to HIDS from these servers.
Divide and Conquer
3 REPLIES 3
Peter Godron
Honored Contributor

Re: HIDS client other than HP-UX

Derek,
as far as I know there are no idsagents for Solaris etc.

The only thing I can think of right now, would be to open a port on an HP box and send encryted( for security/identification) packets from Sun to HP, which can then log it onto the HIDS admin box.

Bit of a long way round, perhaps a specialist will have a better solution.
Pierre Pasturel
Respected Contributor

Re: HIDS client other than HP-UX

Hi Derek -

We only support the HIDS GUI/CLUI and agent sensor on HPUX. A major portion of our product is tightly integrated with the HPUX kernel audit system, and so a port to another platform would require the same level of integration. A port to linux has been considered in the past, but we feel there are other features we need to address first, such as reporting and automation.

In terms of monitoring syslog, HIDS would have to be enhanced, probably with a new detection template, to support the filtering and forwarding of syslog entries to the HIDS GUI/CLUI. HIDS is designed to look for patterns of misuse or intrusion, and was not meant as a general purpose log forwarding mechanism. However, if there is enough demand for monitoring syslog by our HIDS that can't be easily met with the various syslog management opensource and commercial products out there, we might consider it for a subsequent release. I would need to understand your high level and low level requirements.

Pierre
Derek Whigham_1
Trusted Contributor

Re: HIDS client other than HP-UX

Thanks for that. I need an integrated solution with HP-UX and Linux but this would require HIDS to be supported on Linux
Divide and Conquer