Source: sagan Section: admin Priority: optional Maintainer: Pierre Chifflier Build-Depends: debhelper (>= 9), autotools-dev, dh-autoreconf, pkg-config, libpcre3-dev, libee-dev, libesmtp-dev, libpcap-dev, default-libmysqlclient-dev, libpq-dev, libprelude-dev, liblognorm-dev, libyaml-dev Standards-Version: 4.1.4 Homepage: http://sagan.softwink.com/ #Vcs-Git: git://git.debian.org/collab-maint/sagan.git #Vcs-Browser: http://git.debian.org/?p=collab-maint/sagan.git;a=summary Package: sagan Architecture: any Depends: ${shlibs:Depends}, ${misc:Depends}, adduser, sagan-rules, lsb-base (>= 3.0-6) Description: Real-time System & Event Log Monitoring System Sagan is a multi-threaded, real time system- and event-log monitoring system, but with a twist. Sagan uses a “Snort” like rule set for detecting malicious events happening on your network and/or computer systems. If Sagan detects a potentially bad event, that event can be stored to a Snort database (MySQL/PostgreSQL), send it to a SIEM tool like Prelude, or send an email. Sagan is meant to be used in a ‘centralized’ logging environment, but will work fine as part of a standalone Host IDS system for workstations.