Sagan (software)
{{Short description|Log analysis software}}
{{refimprove|date=October 2014}}
{{Inline citations|date=July 2024}}
{{Infobox software
| title =
| name = Sagan
| logo =
| logo caption =
| screenshot =
| caption =
| collapsible =
| author = Champ Clark III
| developer = Quadrant Information Security
| released =
| discontinued =
| latest release version = 2.0.1
| latest release date = {{release date and age|2021|02|08|df=yes}}
| latest preview version =
| latest preview date =
| programming language = C
| operating system = Unix-like
| platform =
| size =
| language = English
| language count =
| language footnote =
| genre = Log analysis
| license = GNU GPL v2
| website = {{URL|https://quadrantsec.com/sagan_log_analysis_engine}}
| standard =
| AsOf =
| logo_size =
| logo_alt =
| screenshot_size =
| screenshot_alt =
}}
Sagan{{cite web|title=Sagan Main Wiki|url=https://wiki.quadrantsec.com/bin/view/Main/SaganMain|website=Sagan Main Wiki|publisher=Champ Clark|ref=Sagan}} is an open source (GNU/GPLv2) multi-threaded, high performance, real-time log analysis & correlation engine developed by Quadrant Information Security that runs on Unix operating systems. It is written in C and uses a multi-threaded architecture to deliver high performance log & event analysis. Sagan's structure and rules work similarly to the Sourcefire Snort IDS/IPS engine. This allows Sagan to be compatible with Snort or Suricata rule management software and gives Sagan the ability to correlate with Snort IDS/IPS data.
Sagan supports different output formats for reporting and analysis, log normalization, script execution on event detection, GeoIP detection/alerting and time sensitive alerting.
See also
{{Portal|Free Software}}
References
{{Reflist}}
- [https://github.com/shadowbq/sagan-extras/blob/master/sagan_freebsd.howto.md HOWTO build Sagan on FreeBSD]
- [http://traffic.libsyn.com/pauldotcom/PaulDotCom-356-Part1.mp3 Champ Clark talks about Sagan on "Pauldotcom Security weekly" - December, 12th, 2013.]
- [http://handlers.sans.org/gbruneau/papers/Guy_Bruneau_BSides_Ottawa_2014.pdf Log, Log, Log Everything Remotely.]
External links
- [https://quadrantsec.com/sagan_solution/ About Sagan]
- [https://web.archive.org/web/20150721121918/https://wiki.quadrantsec.com/twiki/bin/view/Main/SaganMain Official Sagan Wiki]
- [https://quadrantsec.com/about/blog/sagan_flowbit/ Sagan flowbits]
- [https://quadrantsec.com/about/blog/using_sagan_with_bro_intelligence_feeds/ Using Sagan with Bro Intelligence feeds]
- [https://quadrantsec.com/about/blog/sagan_output_to_other_siems/ Sagan output to other SIEMs.]
{{DEFAULTSORT:Sagan (Software)}}
Category:Free security software
Category:Computer security software
Category:Linux security software