General

I suggest you ...

You've used all your votes and won't be able to post a new idea, but you can still search and comment on existing ideas.

There are two ways to get more votes:

  • When an admin closes an idea you've voted on, you'll get your votes back from that idea.
  • You can remove your votes from an open idea you support.
  • To see ideas you have already voted on, select the “My feedback” filter and select “My open ideas”.
(thinking…)
Reset

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can vote and comment on it.

If it doesn't exist, you can post your idea so others can vote on it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
    1. improve the web interface is a goal for ossec success

      improve the web interface is a goal for ossec suceed

      ossec web interface could make ossec power easy of understand for people out there looking for systems like this

      309 votes
      Vote 0 votes Vote Vote
      Vote
      Sign in
      Check!
      (thinking…)
      Reset
      or sign in with
      • facebook
      • google
        Password icon
        I agree to the terms of service

        You'll receive a confirmation email with a link to create a password (optional).

        Signed in as (Sign out)
        You have left! (?) (thinking…)
      • 180 votes
        Vote 0 votes Vote Vote
        Vote
        Sign in
        Check!
        (thinking…)
        Reset
        or sign in with
        • facebook
        • google
          Password icon
          I agree to the terms of service

          You'll receive a confirmation email with a link to create a password (optional).

          Signed in as (Sign out)
          You have left! (?) (thinking…)
        • Decoder & Rules for auditd Logs

          Auditd provides a *ton* of valuable audit logs for user & process accounting purposes. Adding an auditd decoder (and corresponding a set of rules) to OSSEC would be invaluable to the OSSEC project.

          With this addition, OSSEC would be able to support much more granular rules. For example, alerts could be issued whenever X user(s) issue X command(s) at X time.

          149 votes
          Vote 0 votes Vote Vote
          Vote
          Sign in
          Check!
          (thinking…)
          Reset
          or sign in with
          • facebook
          • google
            Password icon
            I agree to the terms of service

            You'll receive a confirmation email with a link to create a password (optional).

            Signed in as (Sign out)
            You have left! (?) (thinking…)
          • store *what* changed.

            It would be extremely useful if--when OSSEC detected a change via a hash change in files--OSSEC would also recored the actual, textual change that was made to the file (excluding binary files, I would imagine).

            With this functionality in place, it would then be possible for the community to develop custom scripts/queries to diff previous versions to see what changes have been preformed on systems over the past X time period.

            92 votes
            Vote 0 votes Vote Vote
            Vote
            Sign in
            Check!
            (thinking…)
            Reset
            or sign in with
            • facebook
            • google
              Password icon
              I agree to the terms of service

              You'll receive a confirmation email with a link to create a password (optional).

              Signed in as (Sign out)
              You have left! (?) (thinking…)
            • Make use of the inotify equivalent in Free/Net/OpenBSD

              Which is kqueue for Realtime monitoring.

              67 votes
              Vote 0 votes Vote Vote
              Vote
              Sign in
              Check!
              (thinking…)
              Reset
              or sign in with
              • facebook
              • google
                Password icon
                I agree to the terms of service

                You'll receive a confirmation email with a link to create a password (optional).

                Signed in as (Sign out)
                You have left! (?) (thinking…)
              • Add support for knowing who made a change

                Right now it is possible to know what changed, but without correlation it is difficult to say with a high degree of certainty who made the change. It would be nice if OSSEC could tie users to changes.

                63 votes
                Vote 0 votes Vote Vote
                Vote
                Sign in
                Check!
                (thinking…)
                Reset
                or sign in with
                • facebook
                • google
                  Password icon
                  I agree to the terms of service

                  You'll receive a confirmation email with a link to create a password (optional).

                  Signed in as (Sign out)
                  You have left! (?) (thinking…)
                • debian package

                  Work with the debian developers to get ossec packaged for debian (and derivatives).

                  Ref bug: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=361954

                  52 votes
                  Vote 0 votes Vote Vote
                  Vote
                  Sign in
                  Check!
                  (thinking…)
                  Reset
                  or sign in with
                  • facebook
                  • google
                    Password icon
                    I agree to the terms of service

                    You'll receive a confirmation email with a link to create a password (optional).

                    Signed in as (Sign out)
                    You have left! (?) (thinking…)
                  • Allow full confirguration of SMTP service in ossec.conf for SMTP auth including SMTP port

                    Allow full confirguration of SMTP service in ossec.conf for SMTP auth including SMTP port

                    48 votes
                    Vote 0 votes Vote Vote
                    Vote
                    Sign in
                    Check!
                    (thinking…)
                    Reset
                    or sign in with
                    • facebook
                    • google
                      Password icon
                      I agree to the terms of service

                      You'll receive a confirmation email with a link to create a password (optional).

                      Signed in as (Sign out)
                      You have left! (?) (thinking…)
                    • 33 votes
                      Vote 0 votes Vote Vote
                      Vote
                      Sign in
                      Check!
                      (thinking…)
                      Reset
                      or sign in with
                      • facebook
                      • google
                        Password icon
                        I agree to the terms of service

                        You'll receive a confirmation email with a link to create a password (optional).

                        Signed in as (Sign out)
                        You have left! (?) (thinking…)
                      • Implement the Agent table in Mysql

                        Currently its there, its just not being used.

                        31 votes
                        Vote 0 votes Vote Vote
                        Vote
                        Sign in
                        Check!
                        (thinking…)
                        Reset
                        or sign in with
                        • facebook
                        • google
                          Password icon
                          I agree to the terms of service

                          You'll receive a confirmation email with a link to create a password (optional).

                          Signed in as (Sign out)
                          You have left! (?) (thinking…)
                        • Extend realtime checking to monitor new file creation

                          At the moment new files are reported only periodically. Extend realtime checking to monitor new file creation.

                          29 votes
                          Vote 0 votes Vote Vote
                          Vote
                          Sign in
                          Check!
                          (thinking…)
                          Reset
                          or sign in with
                          • facebook
                          • google
                            Password icon
                            I agree to the terms of service

                            You'll receive a confirmation email with a link to create a password (optional).

                            Signed in as (Sign out)
                            You have left! (?) (thinking…)
                          • Errors at: os_lib_syscheck.php

                            Resolve the error messages when try to "Dump database" on "Integrity Checking", appears these:

                            Warning: arsort() expects parameter 1 to be array, null given in /var/www/monitorizacion.locolandia.net/ossec/lib/os_lib_syscheck.php on line 97

                            Warning: Invalid argument supplied for foreach() in /var/www/monitorizacion.locolandia.net/ossec/lib/os_lib_syscheck.php on line 98

                            23 votes
                            Vote 0 votes Vote Vote
                            Vote
                            Sign in
                            Check!
                            (thinking…)
                            Reset
                            or sign in with
                            • facebook
                            • google
                              Password icon
                              I agree to the terms of service

                              You'll receive a confirmation email with a link to create a password (optional).

                              Signed in as (Sign out)
                              You have left! (?) (thinking…)
                            • Maintain a stable and new branch

                              Enterprises often need long release cycles between rollouts. On the other hand, they also need bug fixes. I suggest that a stable branch with only bug fixes be maintained for an extended period and a new branch be maintained with all of the new stuff. Perhaps this could be modeled after Ubuntu or something else that works well.

                              23 votes
                              Vote 0 votes Vote Vote
                              Vote
                              Sign in
                              Check!
                              (thinking…)
                              Reset
                              or sign in with
                              • facebook
                              • google
                                Password icon
                                I agree to the terms of service

                                You'll receive a confirmation email with a link to create a password (optional).

                                Signed in as (Sign out)
                                You have left! (?) (thinking…)
                                planned  ·  0 comments  ·  Admin →
                              • Customize syslog output format

                                Extend the syslog_output configuration to allow the output confguration.
                                - Field severity configurable depending on alert level
                                - format of message defined by user with ossec variables (rule ID, Location, ...)

                                20 votes
                                Vote 0 votes Vote Vote
                                Vote
                                Sign in
                                Check!
                                (thinking…)
                                Reset
                                or sign in with
                                • facebook
                                • google
                                  Password icon
                                  I agree to the terms of service

                                  You'll receive a confirmation email with a link to create a password (optional).

                                  Signed in as (Sign out)
                                  You have left! (?) (thinking…)
                                • Distribute decoders and rules separately from program code

                                  Separating the decoders and rules from the main OSSEC distribution would enable more frequent updates and better community participation. See the Snort project and related programs like Oinkmaster / Pulled-Pork for how this might work.

                                  19 votes
                                  Vote 0 votes Vote Vote
                                  Vote
                                  Sign in
                                  Check!
                                  (thinking…)
                                  Reset
                                  or sign in with
                                  • facebook
                                  • google
                                    Password icon
                                    I agree to the terms of service

                                    You'll receive a confirmation email with a link to create a password (optional).

                                    Signed in as (Sign out)
                                    You have left! (?) (thinking…)
                                  • allow using both "*" and "%Y" in the log <locafilefile> <location>

                                    It could be interesting to use both glob and strtime in the localfile location in ossec.conf.

                                    For exemple it's actually impossible to use this king of configuration:

                                    /var/log/%Y/%m/%d/*/auth.log

                                    Where * will represent servers delivering logs via syslog-ng !

                                    18 votes
                                    Vote 0 votes Vote Vote
                                    Vote
                                    Sign in
                                    Check!
                                    (thinking…)
                                    Reset
                                    or sign in with
                                    • facebook
                                    • google
                                      Password icon
                                      I agree to the terms of service

                                      You'll receive a confirmation email with a link to create a password (optional).

                                      Signed in as (Sign out)
                                      You have left! (?) (thinking…)
                                    • Support for oracle audit trail

                                      OSSEC lacks rules to generate alerts from Oracle audit trails. Oracle is a critical system in most of datacentre and its security is must be taken into account.

                                      17 votes
                                      Vote 0 votes Vote Vote
                                      Vote
                                      Sign in
                                      Check!
                                      (thinking…)
                                      Reset
                                      or sign in with
                                      • facebook
                                      • google
                                        Password icon
                                        I agree to the terms of service

                                        You'll receive a confirmation email with a link to create a password (optional).

                                        Signed in as (Sign out)
                                        You have left! (?) (thinking…)
                                      • Make use of snmptrap for network device configuration change

                                        I have been working on the Cisco configuration change audit. I find the idea of getting the configuration change by an snmptrap notification much more convinient and useful since it will only send the change (no need for diff) and it is also real-time

                                        16 votes
                                        Vote 0 votes Vote Vote
                                        Vote
                                        Sign in
                                        Check!
                                        (thinking…)
                                        Reset
                                        or sign in with
                                        • facebook
                                        • google
                                          Password icon
                                          I agree to the terms of service

                                          You'll receive a confirmation email with a link to create a password (optional).

                                          Signed in as (Sign out)
                                          You have left! (?) (thinking…)
                                          under review  ·  4 comments  ·  Admin →
                                        • Store the block list in a database

                                          So it can be read by external applications, like a web interface or command line utilities.

                                          16 votes
                                          Vote 0 votes Vote Vote
                                          Vote
                                          Sign in
                                          Check!
                                          (thinking…)
                                          Reset
                                          or sign in with
                                          • facebook
                                          • google
                                            Password icon
                                            I agree to the terms of service

                                            You'll receive a confirmation email with a link to create a password (optional).

                                            Signed in as (Sign out)
                                            You have left! (?) (thinking…)
                                          • fix helo smtp hostname (make it configurable)

                                            Alert messages are rejected from my postfix server :

                                            450 4.7.1 <notify.ossec.net>: Helo command rejected: Host not found;

                                            Because of security settings, it checks and refuse invalid hostnames.
                                            It should be configurable to what the user wants, not notify.ossec.net.

                                            15 votes
                                            Vote 0 votes Vote Vote
                                            Vote
                                            Sign in
                                            Check!
                                            (thinking…)
                                            Reset
                                            or sign in with
                                            • facebook
                                            • google
                                              Password icon
                                              I agree to the terms of service

                                              You'll receive a confirmation email with a link to create a password (optional).

                                              Signed in as (Sign out)
                                              You have left! (?) (thinking…)
                                            ← Previous 1 3 4 5
                                          • Don’t see your idea?
                                          • Post a new idea…
                                          • General

                                            Knowledge Base and Helpdesk