thank you very much!

this helped alot!

Mit freundlichen Grüßen


Sebastian Kösters

systems architect
Trade Haven GmbH
In der Steele 37,      40599 Düsseldorf
T +49 211 749659 14    mailto:[EMAIL PROTECTED]
F +49 211 749659 29    http://www.tradehaven.de
--------------------------------------------------------------------
Geschäftsführer: Michael Heck | Oliver Wagner Handelsregister Düsseldorf:  HRB 
53379



Daniel Cid schrieb:
> Hi Sebastian,
>
> It is certainly possible. Take a look at:
>
> http://www.ossec.net/wiki/index.php/Know_How:CustomActiveResponses
>
> We pass the alert id and rule id to the scripts, so you can get all
> the information you need. This
> script has an example (to send emails via the active response):
>
> http://www.ossec.net/wiki/index.php/Know_How:CustomActiveResponses#3-Create_active_response_script
>
>
> Hope it helps.
>
> --
> Daniel B. Cid
> dcid ( at ) ossec.net
>
>
>
> On Mon, Apr 7, 2008 at 8:20 AM, skoesters <[EMAIL PROTECTED]> wrote:
>   
>>  Hi,
>>
>>  i would like to do something special, but i dont know if it works and
>>  if yes, how it works.
>>
>>  i would like to create an active response script that sends messages
>>  to nagios monitoring software.
>>
>>  this works to 80%.
>>
>>  at the moment this works like this.
>>
>>  ossec.conf:
>>
>>  <command>
>>     <name>nagios</name>
>>     <executable>nagios.sh</executable>
>>     <timeout_allowed>no</timeout_allowed>
>>     <expect></expect>
>>  </
>>  command>
>>  <!-- Active Response Config -->
>>   <active-response>
>>     <command>nagios</command>
>>     <location>local</location>
>>     <rules_id>110011</rules_id>
>>  </active-response>
>>
>>  rule 110011:
>>
>>
>>  <group name="nagios,">
>>  <rule id="110010" level="0">
>>     <decoded_as>nagios</decoded_as>
>>     <description>nagios rules</description>
>>   </rule>
>>
>>  <rule id="110011" level="12">
>>     <if_sid>110010</if_sid>
>>     <match>Directory index forbidden by rule</match>
>>     <description>Attempt to access forbidden directory index.</
>>  description>
>>     <group>access_denied,</group>
>>   </rule>
>>  </group>
>>
>>  (this is a testrule for apache and works)
>>
>>  this script is triggered when rule 110010 is hit (nagios.sh):
>>
>>  #!/bin/sh
>>  NAGIOS_SERVER=10.10.150.10
>>  NG_SERVICE_HOST=`hostname -s`
>>  /bin/echo -e "$NG_SERVICE_HOST\tOSSEC\t2\tRC=1 MSG=TEST\n" | /var/
>>  ossec/active-response/bin/send_nsca 10.10.150.10 -c /var/ossec/active-
>>  response/bin/nagios.c
>>  fg
>>
>>
>>  this creates a nagios message with RC=1 and MSG=TEST
>>
>>  ----
>>
>>  i now would like to have that "MSG" is a variable.
>>
>>  this is the alert.log output
>>
>>  --
>>
>>  ** Alert 1207566756.158459: - nagios,access_denied,
>>  2008 Apr 07 13:12:36 (th-office) 10.10.100.55->/var/log/apache2/
>>  error.log
>>  Rule: 110011 (level 12) -> 'Attempt to access forbidden directory
>>  index.'
>>  Src IP: (none)
>>  User: (none)
>>  [Mon Apr 07 13:12:36 2008] [error] [client 10.10.100.44] Directory
>>  index forbidden by rule: /var/www/
>>
>>  ---
>>
>>  i would like to put the <match>Directory index forbidden by rule</
>>  match> (here: Directory index forbidden by rule: /var/www/) from the
>>  rule in a variable and "send" it to the script as $4 for example.
>>
>>  Then i could send the log message because of the rule is fired into
>>  nagios and do not have to set it in the script itself, but i only
>>  found to give the script an action, srcip or user.
>>
>>  I hope you understand what i mean.
>>
>>  Is it possible to do that?
>>
>>  Kind regards and thanks
>>
>>  Sebastian
>>
>>
>>     
>
>   

Reply via email to