转载:http://www.srxh1314.com/2014-sec-company-soc-siem.html
http://www.bugsec.org/1598.html
http://www.rightitnow.com/
https://isc.sans.edu//diary/SAGAN:+An+open-source+event+correlation+system+-+Part+1:+Installation/9184
http://comments.gmane.org/gmane.comp.log.sec.user/1345
http://blog.csdn.net/lhy55040817/article/details/8910161