Honeyd
ArchivedThe Honeyd application normalizes Honeyd events and enables you to analyze Honeyd data. You can further customize the searches to perform in-depth analysis.
Release Details
Package Details
- Normalization Package
- LP_Honeyd
Enhancement
A minor update has been done in the application’s normalizer for better signature handling.
Installation
Follow these steps to install the Honeyd v5.0.0 plugin:
- Download the Honeyd package from the Download section above.
- Add the required Honeyd server as a device in LogPoint.
- Create a collection policy with the Syslog collector and appropriate processing policy.
- Assign the policy to the device.
Log Format
Honeyd
Log Sample
Nov 22 13:40:00 complab7-14 honeyd[5695]: listening promiscuously on eth0: (arp or ip proto 47 or (udp and src port 67 and dst port 68) or (ip )) and not ether src 0:1:1:4:b:6
To export data to LogPoint use Syslog collector on port 514 on the LogPoint server.
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.