User Tools

Site Tools


сервис_ossec

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
сервис_ossec [2020/07/15 16:04]
val [Просмотр отчетов]
сервис_ossec [2025/10/16 15:37] (current)
val [Установка, запуск и подключение агента]
Line 2: Line 2:
  
   * [[https://​ru.wikipedia.org/​wiki/​OSSEC|OSSEC — Википедия]]   * [[https://​ru.wikipedia.org/​wiki/​OSSEC|OSSEC — Википедия]]
- 
   * [[https://​habr.com/​ru/​post/​262479/​|Инструкция:​ внедряем HIDS OSSEC]]   * [[https://​habr.com/​ru/​post/​262479/​|Инструкция:​ внедряем HIDS OSSEC]]
- 
   * [[http://​www.ossec.net/​downloads.html|OSSEC Downloads]]   * [[http://​www.ossec.net/​downloads.html|OSSEC Downloads]]
  
Line 21: Line 19:
 lan# apt install ossec-hids-server lan# apt install ossec-hids-server
  
-lan# /var/ossec/bin/agent_control -l+lan# cat /var/ossec/etc/ossec.conf 
 +</​code><​code>​ 
 +... 
 +    <​email_notification>​yes</​email_notification>​ 
 +    <​email_to>​root@corpX.un</​email_to>​ 
 +    <​smtp_server>​server.corpX.un</​smtp_server>​ 
 +    <​email_from>​ossecm@corpX.un</​email_from>​ 
 +  </​global>​
 ... ...
 </​code>​ </​code>​
Line 45: Line 50:
  
 ==== Установка,​ запуск и подключение агента ==== ==== Установка,​ запуск и подключение агента ====
 +
 +=== Windows ===
 +
 +  * [[https://​www.ossec.net/​docs/​docs/​manual/​installation/​installation-windows.html|Windows Agent Installation]]
 +
 +=== Debian ===
 +
 <​code>​ <​code>​
 server# apt install ossec-hids-agent server# apt install ossec-hids-agent
Line 61: Line 73:
  
 server# /​var/​ossec/​bin/​ossec-control start server# /​var/​ossec/​bin/​ossec-control start
 +
 +server# tail -f /​var/​ossec/​logs/​ossec.log
 </​code>​ </​code>​
  
Line 76: Line 90:
     <!-- Frequency that syscheck is executed (default every 2 hours) -->     <!-- Frequency that syscheck is executed (default every 2 hours) -->
     <​frequency>​300</​frequency>​     <​frequency>​300</​frequency>​
-    <​auto_ignore>​no</​auto_ignore>​+    <​auto_ignore>​no</​auto_ignore> <!-- may not be needed -->
     <​directories check_all="​yes">/​usr/​local/​sbin</​directories>​     <​directories check_all="​yes">/​usr/​local/​sbin</​directories>​
 ... ...
Line 86: Line 100:
  
   * [[https://​www.ossec.net/​docs/​docs/​programs/​ossec-reportd.html|ossec-reportd]]   * [[https://​www.ossec.net/​docs/​docs/​programs/​ossec-reportd.html|ossec-reportd]]
 +  * [[https://​www.ossec.net/​docs/​manual/​output/​reports-email-output.html|Daily E-Mail Reports]]
  
 <​code>​ <​code>​
-lan# cat /​var/​ossec/​logs/​alerts/​alerts.log | /​var/​ossec/​bin/​ossec-reportd -f level 1+lan# cat /​var/​ossec/​logs/​alerts/​alerts.log 
 + 
 +lan# cat /​var/​ossec/​logs/​alerts/​alerts.log | /​var/​ossec/​bin/​ossec-reportd -f level 
 + 
 +lan# cat /​var/​ossec/​logs/​alerts/​alerts.log | /​var/​ossec/​bin/​ossec-reportd -f group authentication -r user srcip
 </​code>​ </​code>​
сервис_ossec.1594818281.txt.gz · Last modified: 2020/07/15 16:04 by val