Sagan User Guide¶
- 1. What is Sagan?
- 2. Installation
- 3. Compiling Sagan
- 4. Syslog Configuration
- 5. Sagan Configuration
- 6. vars
- 7. sagan-core
- 8. processors
- 9. outputs
- 10. rule-files
- 11. Rule syntax
- 12. Rule Keywords
- 12.1. after
- 12.2. alert_time
- 12.3. append_program
- 12.4. blacklist
- 12.5. bluedot
- 12.6. classtype
- 12.7. content
- 12.8. country_code
- 12.9. default_proto
- 12.10. default_dst_port
- 12.11. default_src_port
- 12.12. depth
- 12.13. distance
- 12.14. dynamic_load
- 12.15. email
- 12.16. event_id
- 12.17. external
- 12.18. syslog_facility
- 12.19. flexbits
- 12.20. flexbits_pause
- 12.21. json_content
- 12.22. json_nocase
- 12.23. json_contains
- 12.24. json_pcre
- 12.25. json_meta_content
- 12.26. json_meta_nocase
- 12.27. json_meta_contains
- 12.28. syslog_level
- 12.29. meta_content
- 12.30. meta_depth
- 12.31. meta_distance
- 12.32. meta_offset
- 12.33. meta_nocase
- 12.34. meta_within
- 12.35. msg
- 12.36. nocase
- 12.37. normalize
- 12.38. offset
- 12.39. parse_dst_ip
- 12.40. parse_port
- 12.41. parse_proto
- 12.42. parse_proto_program
- 12.43. parse_hash
- 12.44. parse_src_ip
- 12.45. pcre
- 12.46. priority
- 12.47. program
- 12.48. reference
- 12.49. rev
- 12.50. sid
- 12.51. syslog_tag
- 12.52. threshold
- 12.53. within
- 12.54. xbits
- 12.55. xbits_pause
- 12.56. xbits_upause
- 12.57. zeek-intel
- 13. Sagan Peek
- 14. Sagan & JSON
- 15. Journald
- 16. High Performance Considerations
- 17. Contributing & Coding Style
- 18. Sagan Blogs
- 19. Articles about Sagan
- 20. Getting help
- 21. TODO