User Tools

Site Tools


сервис_ossec

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
сервис_ossec [2020/07/15 13:35]
val
сервис_ossec [2024/05/15 10:32] (current)
val [Контроль целостности файлов]
Line 2: Line 2:
  
   * [[https://​ru.wikipedia.org/​wiki/​OSSEC|OSSEC — Википедия]]   * [[https://​ru.wikipedia.org/​wiki/​OSSEC|OSSEC — Википедия]]
- +  ​* [[https://habr.com/​ru/​post/​262479/|Инструкция: внедряем HIDS OSSEC]]
-  ​* [[http://forum.lissyara.su/viewtopic.php?​t=9588|www.lissyara.su - статья об OSSEC]] +
-  * [[http://​ossec-docs.readthedocs.io/​en/​latest/​manual/​agent/​agent-management.html|Managing Agents]] +
-  * [[http://​ossec-docs.readthedocs.io/​en/​latest/​faq/​syscheck.html|Syscheck:​ FAQ - How to force an immediate syscheck scan?]] +
   * [[http://​www.ossec.net/​downloads.html|OSSEC Downloads]]   * [[http://​www.ossec.net/​downloads.html|OSSEC Downloads]]
  
Line 29: Line 25:
 ==== Настройка сервера для подключения агента ==== ==== Настройка сервера для подключения агента ====
 <​code>​ <​code>​
-lanr# /​var/​ossec/​bin/​manage_agents+lan# /​var/​ossec/​bin/​manage_agents
 ... ...
    (A)dd an agent (A).    (A)dd an agent (A).
Line 47: Line 43:
  
 ==== Установка,​ запуск и подключение агента ==== ==== Установка,​ запуск и подключение агента ====
 +
 +=== Windows ===
 +
 +  * [[https://​www.ossec.net/​docs/​docs/​manual/​installation/​installation-windows.html|Windows Agent Installation]]
 +
 +=== Debian ===
 +
 <​code>​ <​code>​
 server# apt install ossec-hids-agent server# apt install ossec-hids-agent
Line 70: Line 73:
 ... ...
 </​code>​ </​code>​
 +==== Контроль целостности файлов ====
 +<​code>​
 +server# cat /​var/​ossec/​etc/​ossec.conf
 +</​code><​code>​
 +...
 +  <​syscheck>​
 +    <!-- Frequency that syscheck is executed (default every 2 hours) -->
 +    <​frequency>​300</​frequency>​
 +    <​auto_ignore>​no</​auto_ignore>​ <!-- may not be needed -->
 +    <​directories check_all="​yes">/​usr/​local/​sbin</​directories>​
 +...
 +</​code><​code>​
 +server# /​var/​ossec/​bin/​ossec-control restart
 +</​code>​
 +
 ==== Просмотр отчетов ==== ==== Просмотр отчетов ====
  
   * [[https://​www.ossec.net/​docs/​docs/​programs/​ossec-reportd.html|ossec-reportd]]   * [[https://​www.ossec.net/​docs/​docs/​programs/​ossec-reportd.html|ossec-reportd]]
 +  * [[https://​www.ossec.net/​docs/​manual/​output/​reports-email-output.html|Daily E-Mail Reports]]
  
 <​code>​ <​code>​
-lan# cat /​var/​ossec/​logs/​alerts/​alerts.log | /​var/​ossec/​bin/​ossec-reportd -f level 1+lan# cat /​var/​ossec/​logs/​alerts/​alerts.log 
 + 
 +lan# cat /​var/​ossec/​logs/​alerts/​alerts.log | /​var/​ossec/​bin/​ossec-reportd -f level 
 + 
 +lan# cat /​var/​ossec/​logs/​alerts/​alerts.log | /​var/​ossec/​bin/​ossec-reportd -f group authentication -r user srcip
 </​code>​ </​code>​
сервис_ossec.1594809328.txt.gz · Last modified: 2020/07/15 13:35 by val