Assuming I have FreeBSD auditd / auditdistd logs.. is there any ruleset or process that looks for oddities and can alert? Generally, what is a reasonable way for security monitoring #FreeBSD?

cc @stefano

@robinp boosting it to make it more visible to FreeBSD people
@robinp @stefano I would go with logcheck which is not BSD related. But there is no easy silver bullet and a lot of work is needed to baseline the normal things.
@stefano @robinp SANS has some good guides in this topic