Ossec is an open source host-based intrusion detection system that performs log analysis, file integrity checking, policy monitoring, rootkit detection and process monitoring.
The best feature of OSEC for me personally was being able to use python scripts which allowed us as DevOps people to automate processes in our environment without having any IT/Network support at all! This also helps with creating an automated workflow where we can run tests against each other servers before they go live (this has saved many hours). I dislike how much easier it would be if you had better documentation about some functions such as finding files by searching directories etc. For…
Pros
If anyone wants screenshots let them ask via PM / email because my original post wasn;'