This documentation is intended to help total newbies to get started with OSSIM (Open Source Security Information Management). Ossim does have existing documentation but it is heavy going for newbies. So I will give links to the docs where they exist and add help where I think it is needed. First grab the latest AlienVault OSSIM Installer from the download page: http://ossim.net/download.php (note that AlienVault is the company behind the OSSIM project). Boot from the ISO cd and it will ask you a few questions: * Country * Timezone * Keyboard Layout * (optional) Main interface, if more than one available. * Root password * Selected interface IP, mask, GW and DNS. Ossim is based on the Debian Linux distro and you may find these commands useful. This is the network diagram for the small network that I will be implementing OSSIM on: Once the installation is done (this is the easy bit) , we start to configure the system. [1] Configure the interfaces [2] Configure ntop [3] Configure snort [4] Configure NAGIOS This document by Ashar |
