
QUICKSTART instructions:

	rpm's are available at the download site
	http://www.speakeasy.org/~roux/dmn

----------------------------------------------------------------------------
 1) Unpack the distribution in a convienient place.			    |
 2) type "make easy"							    |
 3) read the documentation.	(README or "man firelogd")		    |
									    |
 Firelogd should now be quietly waiting for hits on your firewall. It will  |
 send you email when the default number of hits is reached (default 10).    |
 Go read the man page...it is short.					    |
									    |
----------------------------------------------------------------------------

DO NOT USE MAKE EASY IF:
    you do not have syslog (/etc/syslog.conf)
    you do not use SYSV init (/etc/rc.d/rc.init/syslog restart)

    "make easy" was tested on RedHat 6.2, if you have a different distribution
    you should read the section below to make sure things will get installed
    correctly.
_______________________________________________________    

If you had any trouble or you want to do it yourself:

	1. Edit the file "dmn.h" to match your preference.
	   The defaults should work on most installations.
	   	
		(1) Make sure that "MAILCMD" works on your system.
		(2) Set BUFFERSIZE to something reasonable for you.
		    -this can be overridden at the command line.
		(3) Change the log source (LOGFILE) if you want.
		    -this can be overridden at the command line.
		(4) Set the MAILTARGET if root won't work for you
		    -this can be overridden at the command line.
	
	2. If you didn't change the log source enter the command:
		mkfifo /var/log/kernelpipe
		
	3. Edit /etc/syslog.conf and add the line:
		kern.info		|/var/log/kernelpipe
	
	4. If you want to use the precompiled binary, put it somewhere.
		-- OR --
		Build the sources and install:
		"make install" - will put it in /usr/sbin
		it will also attempt to set up your init scripts
		and install the template and lookup files in /etc
		
	8. Run the program:
		firelogd
			*no options prints to screen
			-d		become a daemon (default mailbuffer
							and email address)
							
			-b<size>	set mailbuffer size , become a daemon
					(default mailbuffer size is 10)
					
			-e<mail>	specify the email address for alerts
					(default email is root@localhost)
					
			-		take log data on stdin for parsing
			-k		kill the firelogd daemon process
			-m		mixed logs (tables and chains)
			-s		disable extended port/service lookup
			-l<log>		specify the log file or FIFO
					(default is /var/log/kernelpipe)
					
			-t<template>	specify the output template (default
					is /etc/firelog.conf)
					
	9. ICMP info and TCP/UDP port/service lookup functions.
		If you want to get icmp lookup data you should move the file
		iana-icmp-numbers in the installation directory to /etc/iana-
		icmp-numbers.
		If you want to use the extended iana-port-numbers lookup
		file instead of the system default /etc/services, you need
		to move it to /etc also. You can replace this file with one
		that will give you more information on trojans/backdoors if
		you like. For example, if you have nmap (www.insecure.org)
		you can use the nmap-services file by copying it to
		/etc/iana-port-numbers or change the hardcoded file location
		in the source (dmn.h) to point to your location.

		If you want to temporarily disable the use of the extended
		port lookups, you can invoke the program with the "-s" option.

	10. Output preprocessor templates:
		In the TEMPLATES file of the install directory you will find
		a few examples of how to specify an output template. You will
		need to provide the template filename to the program on the
		command line if you do not want the default output format.
		If you install your template file as /etc/firelog.conf it will
		be read in for you at program startup without having to use
		the "-t" option at the command line.

	11. Add the program to your startup scripts. "make install" will
		attempt to put a startup script in /etc/rc.d/init.d/ for
		you.


 If you have any trouble let me know.
 Ian Jones - roux@speakeasy.org
