How to Install and Uninstall sagan-rules Package on Ubuntu 20.10 (Groovy Gorilla)

Last updated: April 30,2024

1. Install "sagan-rules" package

This guide let you learn how to install sagan-rules on Ubuntu 20.10 (Groovy Gorilla)

$ sudo apt update $ sudo apt install sagan-rules

2. Uninstall "sagan-rules" package

In this section, we are going to explain the necessary steps to uninstall sagan-rules on Ubuntu 20.10 (Groovy Gorilla):

$ sudo apt remove sagan-rules $ sudo apt autoclean && sudo apt autoremove

3. Information about the sagan-rules package on Ubuntu 20.10 (Groovy Gorilla)

Package: sagan-rules
Architecture: all
Version: 1:20170725-1
Priority: extra
Section: universe/admin
Origin: Ubuntu
Maintainer: Ubuntu Developers
Original-Maintainer: Pierre Chifflier
Bugs: https://bugs.launchpad.net/ubuntu/+filebug
Installed-Size: 3150
Filename: pool/universe/s/sagan-rules/sagan-rules_20170725-1_all.deb
Size: 219352
MD5sum: ca404e7f6639e9c6ed6cdba8f02828fe
SHA1: 37ffb8061cd1220f6dcbf2c723ff352fd8a3c117
SHA256: 1c6d03a62a952cb60c6df9daf797bb2e0fee722c2d8edd5490a4be482d0ab428
SHA512: 813e0e2e031d3a8608400d59494b044270cdd9924252ee397dad68df4f5e1d0ac804596fb9ae1742e06e653b34c6840acad09c2e8b818d823d5259ac64b0e4bc
Homepage: https://quadrantsec.com/sagan_log_analysis_engine/
Description-en: Real-time System & Event Log Monitoring System [rules]
Sagan is a multi-threaded, real time system- and event-log monitoring
system, but with a twist. Sagan uses a “Snort” like rule set for
detecting malicious events happening on your network and/or computer
systems.
If Sagan detects a potentially bad event, that event can be stored to a
Snort database (MySQL/PostgreSQL), send it to a SIEM tool like Prelude,
or send an email.
.
This package provides the rules for Sagan.
Description-md5: 9a71019afb085798538636d7822b70d5