Key | Value |
---|---|
FileSize | 226532 |
MD5 | F860DB4F29765A31B225789F8955368C |
PackageDescription | Security Information and Events Management System [ Log Agent ] The Prelude Log Monitoring Lackey (LML) is the host-based sensor program part of the Prelude SIEM suite. It can act as a centralized log collector for local or remote systems, or as a simple log analyzer (such as swatch). It can run as a network server listening on a syslog port or analyze log files. It supports logfiles in the BSD syslog format and is able to analyze any logfile by using the PCRE library. It can apply logfile-specific analysis through plugins such as PAX. It can send an alert to the Prelude Manager when a suspicious log entry is detected. |
PackageMaintainer | Pierre Chifflier <pollux@debian.org> |
PackageName | prelude-lml |
PackageSection | admin |
PackageVersion | 5.2.0-2 |
SHA-1 | 5E99D0083267BB7627FE18C920D1DEE65975C3D5 |
SHA-256 | A770E8A2A3EB42345A6D05AE7192B95C17572C1FFAE06D04A940916D78179FB7 |
hashlookup:children-total | 16 |
hashlookup:trust | 50 |
The searched file hash includes 16 children files known and seen by metalookup. A sample is included below:
Key | Value |
---|---|
FileName | ./usr/share/doc/prelude-lml/changelog.gz |
FileSize | 137987 |
MD5 | B8EBABA1651CCD7E59E9B39F7E2D1A44 |
SHA-1 | 034354933B974C012E66B8AB804C95860A31FF4E |
SHA-256 | BEA7810214DE662B66F22038E98C9C94472F6D3CA100E2D2417270E839817953 |
SSDEEP | 3072:G/qLSN0y6DgAEAQ4oJmYkmIIBqsk6OP2BpDNSbgAyWTmOtY:GSm66tkmIIBC6eOtNS3pY |
TLSH | T176D3127792603853DBD726278AE5E1F2BECF64BA498BFDA050349DFE818357404D2583 |
Key | Value |
---|---|
FileName | ./usr/share/doc/packages/prelude-lml/HACKING.README |
FileSize | 780 |
MD5 | CE979EC4C4C9FD55949BA6867F0EB356 |
SHA-1 | 2D6ACFF0197B79132F46DBE5FAFAC14975C0E1F0 |
SHA-256 | 5CE75927A9FE75588107C5E2A7BF5979807A22A5AA9F21DFB3EB7497F9FB6DDB |
SSDEEP | 12:hBe+oVOrqLRh15X2voInFi2yE0MevyCmFQMl9Kr1yAHkxbpfgtthcAkU5tDWg2:XywrqLvzHIE2M5yCmFjqNHkxNEeAvW |
TLSH | T13E01F11EF36C62A8254609917282E3F6A20F41DACB214431E116D4C533BAA7E853F5DD |
Key | Value |
---|---|
FileName | ./usr/share/doc/prelude-lml/changelog.Debian.gz |
FileSize | 3458 |
MD5 | D2C8707D8C3568BA5717C610185EB704 |
SHA-1 | 416AE6977859E9A95C81B52C7671C5FDFCBDDAB4 |
SHA-256 | 51CAA4D0ACA61620C1FBCC483100FF9D2C4BB4AE9A8C5E14E92928ADA01ED8BD |
SSDEEP | 96:TZAx2jYG7JcxNwF6lXUwU+FXqf/HaLTInQri1D6w:OojNi9VU5+wvhneg |
TLSH | T1F7618F931A02F7F58D199EF974CDF5257A1DE3B850BDB05C10D4254FA05483E46820FD |
Key | Value |
---|---|
FileName | ./usr/share/doc/prelude-lml/README.Debian |
FileSize | 517 |
MD5 | 1298A4E7F1407B397C009E970A0EA593 |
SHA-1 | 487955E33B167AA2C765B8B1BC951E55608DC0BA |
SHA-256 | 2FC3B69E22C20B480C2AA5B833AD58E4BB3096BF6AC1D2EEA10F0327426B581B |
SSDEEP | 12:nkcoBHPyNmY/m5LaR9dEB+EsRFkcvhY1V2kK0huKIcKe/m9:QNKmY/m5LudEB+EsbhCfK0huKIcKeu9 |
TLSH | T1F9F09EE66DCD788511F0DBEAF022C090D65BFC5E50407131700CE1EE410234C05CE210 |
Key | Value |
---|---|
FileName | ./usr/bin/prelude-lml |
FileSize | 136800 |
MD5 | F7588BDB04659FA6EDDC59CF26AD4696 |
SHA-1 | 60E86E712BFBA29C7F8A8BA41671CC8AA7117663 |
SHA-256 | 710C0EA2F7757C61ABEFD31C0034EAD26C4969DD31CCBFD77CC8A05AF47AF396 |
SSDEEP | 3072:QC1W2IQmyWu86qEDZoXOXzPcFec5ecDLi:X1QTyz8zQKXaz8Zlni |
TLSH | T1FAD32A49F746D4B5F2E205F8075B83A2A9305109E363F6A2FE0C676C343935DAE26375 |
Key | Value |
---|---|
FileName | ./usr/lib/i386-linux-gnu/prelude-lml/pcre.so |
FileSize | 42560 |
MD5 | 6176213C02C8B9FA8257F09F41580984 |
SHA-1 | 67C7ECF74F77D78D4D06F58A76816293251D1692 |
SHA-256 | C40A82D9D4530C72AE2E9617DCE06FE4AFE91A442BC4FB00516849450AB961FE |
SSDEEP | 768:J3vqGcyTAc92fTRlHCcbnBzc1ri5AYHMPjwgF0xAhH0anFe:tvqGcyTAcwtXbnBari5AYsrfqZ0 |
TLSH | T12013195BB3C2C8F5F5A307F98E1B8279A574810691A3F1E1FE0973997472318E936239 |
Key | Value |
---|---|
FileName | ./usr/share/doc/prelude-lml/copyright |
FileSize | 7042 |
MD5 | FD3812A430FE63F003C96F99CD0161BB |
SHA-1 | 77CCAFEDD12E5C02306373C6DD53FF79E61163C6 |
SHA-256 | 50A5508C4A8FCD0B26167DF51CD1DE94A014AE1ACDA2D9350B5818E6785289D7 |
SSDEEP | 192:x4PE6LOrXc3vlRH3o13hy5pWo/z4zqeFs:xSE6ars3vvXqhUWo/z4zqeFs |
TLSH | T1F6E1964E1A40C7BB19C01BA0394F95DAE31757EE767EC490105E938E9E0BB3A27F64D4 |
Key | Value |
---|---|
FileName | ./usr/share/doc/prelude-lml/NEWS.gz |
FileSize | 10715 |
MD5 | BB6531860D1CE9E30ED71E422F34791B |
SHA-1 | 9A0E6FADCE0C9DACD9EC9E80CAC69640C9D498F6 |
SHA-256 | 90F121310BCB4188334A80A85E69EC32A7A50C4686E56D9B2ABC88AB8695DB56 |
SSDEEP | 192:bwdYusZzHnVekEctQdvpZqDRlMjpyrbKS+b19r0nOhsiSfF05Nh1r:nVZVYctQtpZIMjGK5TvSINb |
TLSH | T1D922AF9AB116CFA50D85A6E42D47E8057CB72CEDF0938AA45B4E52C287C88B5841F8F8 |
Key | Value |
---|---|
FileName | ./lib/systemd/system/prelude-lml.service |
FileSize | 152 |
MD5 | 8C583644419BCD84F97511F76D10284A |
SHA-1 | 9E329CC69398403460EDDA0CDA307153F7980D0A |
SHA-256 | B1833CB9E3EAE96398A4645ED706256053E9BA15B6EE81F4ABED3BFC2200DD66 |
SSDEEP | 3:zMZa7+rUSXABlRVGmDMzdK+aQ9sHSdS5czTLESkQmWA1+DRvn:z8tU6wlzGmDMzdK+aG858ILQmWA4Rv |
TLSH | T1C3C08C29F48064A0980A2AABCE724BA85A504508AF8DF82436A124291AC0656A4348A9 |
Key | Value |
---|---|
FileName | ./usr/lib/i386-linux-gnu/prelude-lml/debug.so |
FileSize | 13700 |
MD5 | 7BEFF557CB29DD4BD4243DA634274102 |
SHA-1 | CA4DEBB18BC7CFB77397746EA51F550FFE18CC61 |
SHA-256 | C575989C1BA91952EBC9B48C8336D216F43138106BFD3EAB5D473F9C3021C313 |
SSDEEP | 96:Roar2rBWBcO9Zji8X3Qa/c2U/l7mMIbvji+KEqnA3kikFz3V560XUyPI:Rtr+8RX3Qgc2U/lqbLaikZV |
TLSH | T1AA52C616BAA6D573C292033885974BB965368015C3E3C333FF28335828A2794FD63738 |