Source: logdata-anomaly-miner Section: admin Priority: optional Maintainer: Markus Wurzenberger Build-Depends: debhelper-compat (= 13), dh-python, docbook-xsl, docbook-xml, python3, xsltproc Standards-Version: 4.5.1 Homepage: https://aecid.ait.ac.at/ Vcs-Git: https://github.com/ait-aecid/logdata-anomaly-miner.git Vcs-Browser: https://github.com/ait-aecid/logdata-anomaly-miner Rules-Requires-Root: no Package: logdata-anomaly-miner Architecture: all Depends: ${python3:Depends}, python3-tz, ${misc:Depends}, python3-cerberus, python3-pkg-resources, python3-setuptools Suggests: python3-scipy Description: tool for log analysis pipelines This tool allows one to analyze log data streams and detect violations or anomalies in it. It can be run from console, as daemon with e-mail alerting, or embedded as library into own programs. It was designed to run the analysis with limited resources and lowest possible permissions to make it suitable for production server use. Analysis methods include: . * log line parsing and filtering with extended syntax and options * detection of new data elements (IPs, user names, MAC addresses) * statistical anomalies in log line values and frequencies * correlation rules between log lines . The tool is suitable to operate as a sensor feeding a SIEM and distributing messages via message queues.