Key | Value |
---|---|
FileSize | 214832 |
MD5 | 92FAB738DA8A2F4305D21FA1C7A193DC |
PackageDescription | Security Information and Events Management System [ Log Agent ] The Prelude Log Monitoring Lackey (LML) is the host-based sensor program part of the Prelude SIEM suite. It can act as a centralized log collector for local or remote systems, or as a simple log analyzer (such as swatch). It can run as a network server listening on a syslog port or analyze log files. It supports logfiles in the BSD syslog format and is able to analyze any logfile by using the PCRE library. It can apply logfile-specific analysis through plugins such as PAX. It can send an alert to the Prelude Manager when a suspicious log entry is detected. |
PackageMaintainer | Pierre Chifflier <pollux@debian.org> |
PackageName | prelude-lml |
PackageSection | admin |
PackageVersion | 5.2.0-2 |
SHA-1 | B5B03266447515CC81654341B1E24FE0078CC071 |
SHA-256 | 1E404D413CF92BF83C2AE1B956089FF1A2E6DC286DB2F469FABAFFC29FF50AD4 |
hashlookup:children-total | 16 |
hashlookup:trust | 50 |
The searched file hash includes 16 children files known and seen by metalookup. A sample is included below:
Key | Value |
---|---|
FileName | ./usr/share/doc/prelude-lml/changelog.gz |
FileSize | 137987 |
MD5 | B8EBABA1651CCD7E59E9B39F7E2D1A44 |
SHA-1 | 034354933B974C012E66B8AB804C95860A31FF4E |
SHA-256 | BEA7810214DE662B66F22038E98C9C94472F6D3CA100E2D2417270E839817953 |
SSDEEP | 3072:G/qLSN0y6DgAEAQ4oJmYkmIIBqsk6OP2BpDNSbgAyWTmOtY:GSm66tkmIIBC6eOtNS3pY |
TLSH | T176D3127792603853DBD726278AE5E1F2BECF64BA498BFDA050349DFE818357404D2583 |
Key | Value |
---|---|
FileName | ./usr/share/doc/packages/prelude-lml/HACKING.README |
FileSize | 780 |
MD5 | CE979EC4C4C9FD55949BA6867F0EB356 |
SHA-1 | 2D6ACFF0197B79132F46DBE5FAFAC14975C0E1F0 |
SHA-256 | 5CE75927A9FE75588107C5E2A7BF5979807A22A5AA9F21DFB3EB7497F9FB6DDB |
SSDEEP | 12:hBe+oVOrqLRh15X2voInFi2yE0MevyCmFQMl9Kr1yAHkxbpfgtthcAkU5tDWg2:XywrqLvzHIE2M5yCmFjqNHkxNEeAvW |
TLSH | T13E01F11EF36C62A8254609917282E3F6A20F41DACB214431E116D4C533BAA7E853F5DD |
Key | Value |
---|---|
FileName | ./usr/share/doc/prelude-lml/changelog.Debian.gz |
FileSize | 3458 |
MD5 | D2C8707D8C3568BA5717C610185EB704 |
SHA-1 | 416AE6977859E9A95C81B52C7671C5FDFCBDDAB4 |
SHA-256 | 51CAA4D0ACA61620C1FBCC483100FF9D2C4BB4AE9A8C5E14E92928ADA01ED8BD |
SSDEEP | 96:TZAx2jYG7JcxNwF6lXUwU+FXqf/HaLTInQri1D6w:OojNi9VU5+wvhneg |
TLSH | T1F7618F931A02F7F58D199EF974CDF5257A1DE3B850BDB05C10D4254FA05483E46820FD |
Key | Value |
---|---|
FileName | ./usr/share/doc/prelude-lml/README.Debian |
FileSize | 517 |
MD5 | 1298A4E7F1407B397C009E970A0EA593 |
SHA-1 | 487955E33B167AA2C765B8B1BC951E55608DC0BA |
SHA-256 | 2FC3B69E22C20B480C2AA5B833AD58E4BB3096BF6AC1D2EEA10F0327426B581B |
SSDEEP | 12:nkcoBHPyNmY/m5LaR9dEB+EsRFkcvhY1V2kK0huKIcKe/m9:QNKmY/m5LudEB+EsbhCfK0huKIcKeu9 |
TLSH | T1F9F09EE66DCD788511F0DBEAF022C090D65BFC5E50407131700CE1EE410234C05CE210 |
Key | Value |
---|---|
FileName | ./usr/share/doc/prelude-lml/copyright |
FileSize | 7042 |
MD5 | FD3812A430FE63F003C96F99CD0161BB |
SHA-1 | 77CCAFEDD12E5C02306373C6DD53FF79E61163C6 |
SHA-256 | 50A5508C4A8FCD0B26167DF51CD1DE94A014AE1ACDA2D9350B5818E6785289D7 |
SSDEEP | 192:x4PE6LOrXc3vlRH3o13hy5pWo/z4zqeFs:xSE6ars3vvXqhUWo/z4zqeFs |
TLSH | T1F6E1964E1A40C7BB19C01BA0394F95DAE31757EE767EC490105E938E9E0BB3A27F64D4 |
Key | Value |
---|---|
FileName | ./usr/bin/prelude-lml |
FileSize | 87620 |
MD5 | 9E0BE7C530696F674153605EFAA0A220 |
SHA-1 | 8009AF45402FC09EF1727CE81F4726926EED5F39 |
SHA-256 | B09C6175AAD2A80250B3E32647C451C691E751E50AD1D344F1550F3BD96E70C1 |
SSDEEP | 1536:sQK5n88V9+Bv6UQ+lh639YMMc+iGuYqy/j+pe:s/nScUQCgyp/jm |
TLSH | T133838DE7B8574D1FE9C106BB4117AE5007625BCCD3865F2F281C41B8090DAADBE6EB93 |
Key | Value |
---|---|
FileName | ./usr/lib/arm-linux-gnueabihf/prelude-lml/pcre.so |
FileSize | 26156 |
MD5 | 470998F018C44E3FAB56998FE292DD3C |
SHA-1 | 839490487366CDBC1B370B8E6ADD88F9F9EC2B99 |
SHA-256 | 8C7DAF1C68FA7DF30E4AC3B6D137CD7D6338A9FD7119AFFD1A0E03E0220E0792 |
SSDEEP | 384:W0axpGcCTAc20sZP5PRgLuvHiWQrHRaweLqklNJw+1Xdccdkt0lYevLV:faxpGcCTAcwPhqZrHEwt+1gAL |
TLSH | T138C2F8D4B02F8E27CDD062B9DF6A4F4066E0818F4296DF21AD28D1B41FCD56C8D67D26 |
Key | Value |
---|---|
FileName | ./usr/share/doc/prelude-lml/NEWS.gz |
FileSize | 10715 |
MD5 | BB6531860D1CE9E30ED71E422F34791B |
SHA-1 | 9A0E6FADCE0C9DACD9EC9E80CAC69640C9D498F6 |
SHA-256 | 90F121310BCB4188334A80A85E69EC32A7A50C4686E56D9B2ABC88AB8695DB56 |
SSDEEP | 192:bwdYusZzHnVekEctQdvpZqDRlMjpyrbKS+b19r0nOhsiSfF05Nh1r:nVZVYctQtpZIMjGK5TvSINb |
TLSH | T1D922AF9AB116CFA50D85A6E42D47E8057CB72CEDF0938AA45B4E52C287C88B5841F8F8 |
Key | Value |
---|---|
FileName | ./lib/systemd/system/prelude-lml.service |
FileSize | 152 |
MD5 | 8C583644419BCD84F97511F76D10284A |
SHA-1 | 9E329CC69398403460EDDA0CDA307153F7980D0A |
SHA-256 | B1833CB9E3EAE96398A4645ED706256053E9BA15B6EE81F4ABED3BFC2200DD66 |
SSDEEP | 3:zMZa7+rUSXABlRVGmDMzdK+aQ9sHSdS5czTLESkQmWA1+DRvn:z8tU6wlzGmDMzdK+aG858ILQmWA4Rv |
TLSH | T1C3C08C29F48064A0980A2AABCE724BA85A504508AF8DF82436A124291AC0656A4348A9 |
Key | Value |
---|---|
FileName | ./usr/share/doc/packages/prelude-lml/README |
FileSize | 1742 |
MD5 | A5924B09DE4B82B6F15A5BE943CA79F2 |
SHA-1 | CBF9D34C6A6077CE6250E1E681663EBFF1E19795 |
SHA-256 | E36B8D95200965696F8FB79B0338C070E7A370B6B52F1227F7187AC201B3B4E0 |
SSDEEP | 24:ykwdzTaLVNECo7w5QlXlunfy1XICIrYKZQgDnJkt8MswCHJfVKcDwaq+ygXA:SwECo7Hlua1XtKZQg1kt8DXJfVsP |
TLSH | T1AE3116FFA2687270734525C87216E0FBCBA375AEE2602571FC9C94D5632A39C4236B85 |