fw1-loggrabber

Version: 1.11.1  Mod Stingley 01
Mark Stingley, mark _AT_ altsec.info
http://www.altsec.info

Original version:

Copyright (c) 2005 Torsten Fellhauer, Xiaodong Lin

This program is free software; you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation; either version 2 of the License, or
(at your option) any later version.

This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
GNU General Public License for more details.

See http://www.gnu.org/licenses/licenses.html#GPL or write to the
Free Software Foundation, Inc., 59 Temple Place, Suite 330, Boston,
MA  02111-1307  USA

See the original GNU Copyright statement in fw1-loggrabber.c or fw1-loggrabber.h.

This modification of the Splunk packaging of fw1-loggrabber 1.11.1 was made to add indexing, reduce the number of fields returned in realtime ODBC mode, and to add the field rule_uid.

For detailed instructions on creation and use see:

http://www.altsec.info/fwlogproj/CPFWLG-Setup-Detailed-20090722.pdf

The Splunk fw1-loggrabber packing (with source code) is at:

http://download.splunk.com/support/OPSEC/fw1loggrabbersplunk.tar.gz

The official project page for fw1-loggrabber is:


INSTRUCTIONS:

If you do not intend to compile your own executables, simply use the included binaries.

fw1-loggrabber-splunk-orig.bin can be renamed to fw1-loggrabber and placed in the desired project directory, such as /opt/loggrabber.  Use this version if you wish to work with the original configuration.

Otherwise, copy fw1-loggrabber-splunk-mod01.bin to fw1-loggrabber in the project directory to take advantage of the indexing, reduced field count, and addition of the rule_uid field.


PATCHING

NOTICE:  No guarantees are expressed or implied.  Use at your own risk.  The patch files will likely only work with the recommended Splunk packaging of fw1-loggrabber 1.11.1 as described.  Be prudent - make backups.

After unpacking the Splunk fw1-loggrabber source gzip tarball, just change to the source code directory and follow the instructions, or substitute your own favorite patching routine:

1.  copy the original fw1-loggrabber.c to fw1-loggrabber.c.orig
2.  run: patch fw1-loggrabber.c fw1-loggrabber-Stingley-MOD-01-patch.c  
3.  copy the original fw1loggrabber.h to fw1-loggrabber.h.orig
4.  run: patch fw1-loggrabber.h fw1-loggrabber-Stingley-MOD-01-patch.h

Then, following the instructions in CPFWLG-Setup-Detailed-20090722.pdf, make the necessary Makefile changes and build the executables, etc.


md5sum for the binaries and patches:

83f188ce115928227260fb3d5b29cb70  fw1-loggrabber-splunk-mod01.bin
0ce35b1fcde4d9018d6aa8f7422effcc  fw1-loggrabber-splunk-orig.bin
a88b97e677a6757b010d9122ddeacda7  fw1-loggrabber-Stingley-MOD-01-patch.c
a984219e6c1026099ab8ee4760939203  fw1-loggrabber-Stingley-MOD-01-patch.h


