thank you very much! this helped alot!
Mit freundlichen Grüßen Sebastian Kösters systems architect Trade Haven GmbH In der Steele 37, 40599 Düsseldorf T +49 211 749659 14 mailto:[EMAIL PROTECTED] F +49 211 749659 29 http://www.tradehaven.de -------------------------------------------------------------------- Geschäftsführer: Michael Heck | Oliver Wagner Handelsregister Düsseldorf: HRB 53379 Daniel Cid schrieb: > Hi Sebastian, > > It is certainly possible. Take a look at: > > http://www.ossec.net/wiki/index.php/Know_How:CustomActiveResponses > > We pass the alert id and rule id to the scripts, so you can get all > the information you need. This > script has an example (to send emails via the active response): > > http://www.ossec.net/wiki/index.php/Know_How:CustomActiveResponses#3-Create_active_response_script > > > Hope it helps. > > -- > Daniel B. Cid > dcid ( at ) ossec.net > > > > On Mon, Apr 7, 2008 at 8:20 AM, skoesters <[EMAIL PROTECTED]> wrote: > >> Hi, >> >> i would like to do something special, but i dont know if it works and >> if yes, how it works. >> >> i would like to create an active response script that sends messages >> to nagios monitoring software. >> >> this works to 80%. >> >> at the moment this works like this. >> >> ossec.conf: >> >> <command> >> <name>nagios</name> >> <executable>nagios.sh</executable> >> <timeout_allowed>no</timeout_allowed> >> <expect></expect> >> </ >> command> >> <!-- Active Response Config --> >> <active-response> >> <command>nagios</command> >> <location>local</location> >> <rules_id>110011</rules_id> >> </active-response> >> >> rule 110011: >> >> >> <group name="nagios,"> >> <rule id="110010" level="0"> >> <decoded_as>nagios</decoded_as> >> <description>nagios rules</description> >> </rule> >> >> <rule id="110011" level="12"> >> <if_sid>110010</if_sid> >> <match>Directory index forbidden by rule</match> >> <description>Attempt to access forbidden directory index.</ >> description> >> <group>access_denied,</group> >> </rule> >> </group> >> >> (this is a testrule for apache and works) >> >> this script is triggered when rule 110010 is hit (nagios.sh): >> >> #!/bin/sh >> NAGIOS_SERVER=10.10.150.10 >> NG_SERVICE_HOST=`hostname -s` >> /bin/echo -e "$NG_SERVICE_HOST\tOSSEC\t2\tRC=1 MSG=TEST\n" | /var/ >> ossec/active-response/bin/send_nsca 10.10.150.10 -c /var/ossec/active- >> response/bin/nagios.c >> fg >> >> >> this creates a nagios message with RC=1 and MSG=TEST >> >> ---- >> >> i now would like to have that "MSG" is a variable. >> >> this is the alert.log output >> >> -- >> >> ** Alert 1207566756.158459: - nagios,access_denied, >> 2008 Apr 07 13:12:36 (th-office) 10.10.100.55->/var/log/apache2/ >> error.log >> Rule: 110011 (level 12) -> 'Attempt to access forbidden directory >> index.' >> Src IP: (none) >> User: (none) >> [Mon Apr 07 13:12:36 2008] [error] [client 10.10.100.44] Directory >> index forbidden by rule: /var/www/ >> >> --- >> >> i would like to put the <match>Directory index forbidden by rule</ >> match> (here: Directory index forbidden by rule: /var/www/) from the >> rule in a variable and "send" it to the script as $4 for example. >> >> Then i could send the log message because of the rule is fired into >> nagios and do not have to set it in the script itself, but i only >> found to give the script an action, srcip or user. >> >> I hope you understand what i mean. >> >> Is it possible to do that? >> >> Kind regards and thanks >> >> Sebastian >> >> >> > >
