#AlienVault #OSSIM getting buried by connect and disconnect messages

Solution is here


File to edit is /etc/ossim/agent/plugins/sonicwall.cfg

add “exclude_sid=” (without quotes) to the sonicwall plugin config and add the SID’s that you don’t want to appear in alienvault. It will nuke them at the agent level. Comma seperated please with no spaces between (ex. exclude_sid=8698251,8699283) you can find the SID number in question by opening the event in the SIEM that you don’t want to keep and looking for (you guessed it) “Event Type ID”

hmm but It doesn’t seem to be filtering yet…. will have to keep stabbing


Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s