Implementing an open source SIEM tool
In this section, you will be learning how to implement AlienVault's Open Source Security Information and Event Management (OSSIM) on a network. OSSIM is a free SIEM solution from AlienVault that allows security professionals to discover assets, perform vulnerability management, detect intrusions, monitor application and device behavior, and handle event/log correlation and alerting.
As you may recall from elsewhere in this book, we have discussed the benefits and functions of implementing a SIEM tool within an enterprise network. One of the major benefits of using a SIEM tool is that it allows cybersecurity professionals to use a single dashboard to view all potential threats within the entire network of their organization.
The following diagram shows a simplified deployment model of an on-premises solution:
As shown in the preceding figure, the SIEM tool is deployed...