Skip to main content
Join the official 2020 Python Developers SurveyStart the survey!

Python bindings for the Prelude Library

Project description

Prelude is a Universal “Security Information & Event Management” (SIEM) system. Prelude collects, normalizes, sorts, aggregates, correlates and reports all security-related events independently of the product brand or license giving rise to such events; Prelude is “agentless”.

As well as being capable of recovering any type of log (system logs, syslog, flat files, etc.), Prelude benefits from a native support with a number of systems dedicated to enriching information even further (snort, samhain, ossec, auditd, etc.).

Prelude standardizes all the notables or suspicious events to IDMEF standard format (RFC 4765). With this format, events are enriched to facilitate automation and correlation processes but also to provide as much information to the operator (contextualization alerts) to allow it to respond quickly and effectively.

Libprelude is a collection of generic functions providing communication between all Sensors, like IDS (Intrusion Detection System), and the Prelude Manager. It provides a convenient interface for sending and receiving IDMEF (Information and Event Message Exchange Format) alerts to Prelude Manager with transparent SSL, fail-over and replication support, asynchronous events and timer interfaces, an abstracted configuration API (hooking at the command-line, the configuration line, or wide configuration, available from the Manager), and a generic plugin API. It allows you to easily turn your favorite security program into a Prelude sensor.

Installing

Install requirements to build the C part:

yum group install "Development Tools"

yum install python-devel

Install and update using pip:

pip install -U prelude

A Simple Example

import prelude

if __name__ == '__main__':
    idmef = prelude.IDMEF()
    idmef.set("alert.classification.text", "Hello world!")
    print(idmef)

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Files for prelude, version 5.1.1
Filename, size File type Python version Upload date Hashes
Filename, size prelude-5.1.1-1.tar.gz (81.3 kB) File type Source Python version None Upload date Hashes View

Supported by

Pingdom Pingdom Monitoring Google Google Object Storage and Download Analytics Sentry Sentry Error logging AWS AWS Cloud computing DataDog DataDog Monitoring Fastly Fastly CDN DigiCert DigiCert EV certificate StatusPage StatusPage Status page