Information:
This is a behavior, anomaly and signature-based syslog intrusion detection system which can detect new, unknown attacks. It fits in a heterogeneous Unix, Linux or BSD environment at the core of a central syslog server. Devialog can generate its own signatures and act upon anomalies as configured by the system administrator. In addition, devialog functions as a traditional syslog parsing utility in which known signatures trigger actions.