Octopussy, also known as 8Pussy, is a free and open-source computer-software which monitors systems, by constantly analyzing the syslog data they generate and transmit to such a central Octopussy server (thus often called a SIEM solution). Therefore, software like Octopussy plays an important role in maintaining an information security management system within ISO/IEC 27001-compliant environments. Octopussy has the ability to monitor any device that supports the syslog protocol, such as servers, routers, switches, firewalls, load balancers, and its important applications and services. The main purpose of the software is to alert its administrators and users to different kinds of events, like system outages, attacks on systems or errors in applications. However, unlike Nagios or Icinga, Octopussy is not a state-checker and therefore problems cannot be resolved within the application. The software also makes no prescription whatsoever on which messages must be/must not be analyzed. As such, Octopussy can be seen as less powerful than other popular commercial software in the same category (event monitoring and log analysis). Octopussy is compatible with many Linux system distributions like Debian, Ubuntu, OpenSUSE, CentOS, RHEL and even meta-distributions as Gentoo or Arch Linux. Although Octopussy was originally designed to run on Linux, it could be ported to other Unix variants like FreeBSD with minimal effort. Octopussy has extensive report generating features and also various interfaces to other software, like e.g. NSCA (Nagios), Jabber/XMPP and Zabbix. With the help of software like Snare even Windows EventLogs can be processed. Octopussy is licensed under the terms of the GNU General Public License.
Characteristics Although Octopussy is free and open-source software it has a variety of characteristics also found in some professional enterprise applications like Splunk, SAWMILL or Kiwi Syslog.
Octopussy features At the time of writing, Octopussy comes with the following set of features:
Basic LDAP support (v1.0+) for Octopussy users and contacts with filter mechanism Alert sending by email, IM (Jabber), NSCA (Nagios) and Zabbix Map functionality to show the system infrastructure known to Octopussy Exportable reports by email, FTP and SCP Input & output plugins for manual and automatic reports Report scheduling and automated report generation based on parameters A log viewer to search for syslog messages received by Octopussy An RRDtool to provide data graphing of syslog activity for enabled services Comprehensive service definitions (Apache 2, BIND, BSD Kernel ...) A wizard to easily create new services and/or message patterns for existing services An option to enable or disable services and alerts for every system under surveillance Online updates for services, tables and l18n (language support) Multi-language support: English French German Italian Spanish Portuguese Russian A web-interface for viewing current devices status, alerts, log messages, etc. A themable interface and report documents Manageability of Octopussy core services from the operating system shell Flat-text formatted configuration files (integrates with many configuration editors) An option to timely rotate and store received syslog messages in various locations User management with the ability of granular permission configuration Simple outline of styles and GUI components in ASP for easy modification
Supported services Some of the (meta-)services supported by/known by Octopussy are: Apache 2, BIND, BSD Kernel, BSD PAM, BSD System, Cisco Routers (ASR), Cisco Switches, ClamAV, DenyAll Reverse Proxy, DRBD, F5 BigIP, Fortinet FW, HP-Tools, Ironport MailServer, Juniper Netscreen FW, Juniper Netscreen NSM, LDAP, Linux AppArmor, Linux Auditd, Linux IPTables, Linux Kernel, Linux PAM, Linux System, Monit, MySQL, Nagios, Neoteris/Juniper FW, NetApp NetCache, Postfix, PostgreSQL, Samba, Samhain, SNMPd, Squid, SSHd, Syslog-ng, TACACS, VMware ESX(i), Windows Snare Agent, Windows System, Xen ...
Processible events Events receivable from services and thus processible by Octopussy include:
Failed and/or successful logins, especially of higher privileged users Violation of access permissions or policies in applications and operating systems Write and/or read access in critical environments, e.g. with AppArmor or SELinux Established or terminated VPN tunnels in systems, like e.g. Juniper Netscreen Objects like processes or files which security context or configuration changed Started or stopped processes on an operating system level Critical system states like (unrecoverable) hardware or software failure Change in operating system state due to boot, reboot or shutdown Information regarding network connections/traffic, including ICMP messages, etc. Detection or otherwise handling of malware (i.e. worms, viruses, trojans)
Dependencies The software requires RSYSLOG installed on the syslog-server and expects systems that are monitored to run one of the numerous available syslog services, like e.g. syslogd/klogd, RSYSLOG or syslog-ng. The software further depends on the Apache 2 HTTP Server installed, with Apache::ASP, Mod_Perl and Mod_SSL. Octopussy also requires a MySQL DBMS (actual database is installed/copied during Octopussy setup) as well as a recent Perl interpreter installed on the operating system, with a variety of Perl modules from CPAN (e.g. Crypt::PasswdMD5, DBD::mysql, JSON, Unix::Syslog, XML::Simple). A comprehensive list of those modules can be found within the software packages/archives README.txt file. In addition to that NSCD and RRDtool are a requirement. RRDtool aids in the creation of graphs that will be displayed on the Octopussy dashboard or shown on a per-device/per-service level.
Architecture
… excerpt ends here. Continue reading the full article.






