Also, how can I tell from within OSSEC *which* device fired an event? I'm monitoring 3 devices: * a Unix box * a Windoze server * a Cisco ASA
None of the OSSEC IDS alerts tell me what system triggered what event. I want to figure this out before I attempt to mass-deploy this. TIA Thanks Dave On 4/16/09, davidr521 <[email protected]> wrote: > > Daniel, > > Thanks *very* much for the quick response. I tried that as well, and > got a timeout error. > > I know that when I puTTY over to my ASA, it asks me to validate the > SSH fingerprint. > > So either way, I'm having a problem.... > > Thoughts welcome > > TIA > > Dave Rosenblatt > davidr521 (at) gmail.com > > On Apr 16, 6:23 pm, Daniel Cid <[email protected]> wrote: >> Hi Dave, >> >> You need to provide a user name in the host field. It should be in the >> format u...@host. Plus, it should >> match what you gave for the register_host. >> >> If you look at our examples, we always use u...@host: >> >> <host>[email protected]</host> >> >> That should solve your problem. >> >> Thanks, >> >> -- >> Daniel B. Cid >> dcid ( at ) ossec.net >> >> On Thu, Apr 16, 2009 at 6:20 PM, Dave <[email protected]> wrote: >> > All, >> >> > I may be a bit of a chowderhead here (it's been known to happen), but >> > I've >> > now spent two days solid trying to wrap my head around getting OSSEC >> > connected to my Cisco ASA. >> >> > A few items of note: >> > * I _don't_ want to change where I'm syslogging >> > * I want to do this agentless >> >> > I have: >> > * Run register_host.sh (# /var/ossec/agentless/register_host.sh add >> > [email protected] mypass1). I'm _assuming_ from everything I'm reading >> > that the >> > syntax is <add asausern...@ip_address_of_asa logonpassword >> > enablepassword> >> > * Modified /var/ossec/etc/ossec.conf as follows: >> > <agentless> >> > <!-- Assuming this will work... [DAR] 04-16-09 --> >> > <type>ssh_pixconfig_diff</type> >> > <frequency>60</frequency> >> > <host>my_ip_address_here</host> >> > <state>periodic_diff</state> >> > </agentless> >> > I'm assuming that I _don't_ have to put the asausername in the <host> >> > clause? But hey, I have no idea. >> > * Restarted OSSEC by running /var/ossec/bin/ossec-control restart >> >> > Here's what I end up with in ossec.log: >> > --------------------------------------------------------------------------- >> > --------------------------------------------------------------------------- >> > 2009/04/16 16:25:35 ossec-agentlessd: ERROR: ssh_pixconfig_diff: >> > my_ip_address_here: Password for 'my_ip_address_here' not found. >> > 2009/04/16 16:26:36 ossec-agentlessd: ERROR: ssh_pixconfig_diff: >> > my_ip_address_here: Password for 'my_ip_address_here' not found. >> > 2009/04/16 16:27:37 ossec-agentlessd: ERROR: ssh_pixconfig_diff: >> > my_ip_address_here: Password for my_ip_address_here' not found. >> > 2009/04/16 16:28:38 ossec-agentlessd: ERROR: Too many failures for >> > 'ssh_pixconfig_diff'. Ignoring it. >> > --------------------------------------------------------------------------- >> > --------------------------------------------------------------------------- >> > Of course, I replace 'my_ip_address_here' with the valid IP address. >> >> > I can ping the box from my OSSEC box. >> >> > What I'm after is what's on the bottom >> > ofhttp://www.ossec.net/dcid/?p=158: >> > --------------------------------------------------------------------------- >> > --------------------------------------------------------------------------- >> > For the PIX: >> > OSSEC HIDS Notification. >> > 2008 Dec 01 15:48:03 >> > Received From: (ssh_pixconfig_diff) [email protected]>agentless >> > Rule: 555 fired (level 7) -> “Integrity checksum for agentless device >> > changed.” >> > Portion of the log(s): >> > ossec: agentless: Change detected: >> > 48c48 >> > < fixup protocol ftp 21 >> > — >> >> no fixup protocol ftp 21 >> > 100c100 >> > < ssh timeout 30 >> > — >> >> ssh timeout 50 >> > More changes.. >> > –END OF NOTIFICATION >> > --------------------------------------------------------------------------- >> > --------------------------------------------------------------------------- >> >> > I fear it's a problem with an SSH fingerprint, but I haven't the >> > foggiest >> > idea how to resolve it. >> >> > I know the email works, because OSSEC sends me a friendly "Hey there!" >> > email >> > whenever I do a restart: >> >> > --------------------------------------------------------------------------- >> > --------------------------------------------------------------------------- >> > OSSEC HIDS Notification. >> > 2009 Apr 16 15:41:55 >> > Received From: OSSIM->ossec-monitord >> > Rule: 502 fired (level 3) -> "Ossec server started." >> > Portion of the log(s): >> > ossec: Ossec started. >> >> > --END OF NOTIFICATION >> > --------------------------------------------------------------------------- >> > --------------------------------------------------------------------------- >> >> > I _really_ need to replace Tr*pwire, and I know OSSEC can do it. Just >> > not >> > sure where to go from here. >> >> > Any help would be *greatly* appreciated. >
