ossec / ossec-hids

OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response.
http://www.ossec.net
Other
4.53k stars 1.04k forks source link

GeoLite2 support? #1401

Open torataks opened 6 years ago

torataks commented 6 years ago

MaxMind stopped updates to its free, legacy GeoIP databases last month. They recommend that users switch to its free GeoLite2 databases. Does OSSEC support the newer MaxMind DB format that is used to publish the GeoLite2 info?

https://dev.maxmind.com/geoip/geoip2/geolite2/

Thanks!

ddpbsd commented 6 years ago

I don't think we currently support GeoLite2. I haven't looked at it, but I imagine it's a fairly straight forward switch if someone wanted to get their feet wet.