OSSIM Components
OSSIM Components
Sensor Collects Information Database Storage for other components Logger (Commercial Only) Complete log
storage
Server
Server is the central component of OSSIM, and performs the key SIEM functions:
Event Correlation Risk Assessment And Prioritization Inventory and Identity Management Alarms and Scheduling Policy Management Reputation Engine
Framework
Framework manages OSSIM components and connects them together. Provides the Web User Interface Manages OSSIM component configurations and communication.
Database
Handles storage for Inventory data, configuration and SIEM events. SIEM Event Storage Asset Storage Continuous Data (netflow, etc) storage Run-time OSSIM Configurations
Sensor (+Agents)
The Information-Gathering component of OSSIM. Agents collect logs and events from external devices and OSSIM monitoring components, using Plugins for each type of information they will collect Log Collection
Fetch and Receive
Network Monitoring
Network Traffic Monitoring Network Intrusion Detection Asset Detection Host Intrusion Detection Wireless Intrusion Detection
Sensor