Or do I even need to install the agent on dhcp workstations? If I create the a.b.c.0/24 with manage_agents, will it monitor everyone on that subnet?
Thanks, Charlie -----Original Message----- From: Bryant, Charlie To: [email protected] <[email protected]> Sent: Sun Dec 13 14:06:23 2009 Subject: RE: {SPAM 06.1} [ossec-list] Agents under DHCP Just tried this. Cool. And of course, it raises another question. Here's my first hit from it. It gives the source IP as a.b.c.0. How do I tell which of my (so far, two) test workstations running the agent from dhcp addresses fired the rule? Thanks. OSSEC HIDS Notification. 2009 Dec 13 13:32:17 Received From: (dhcp) a.b.c.0->rootcheck Rule: 513 fired (level 9) -> "Windows malware detected." Portion of the log(s): Windows Malware: Anti-virus site on the hosts file. File: C:\WINDOWS\System32\Drivers\etc\HOSTS. ________________________________ From: [email protected] on behalf of Jeremy Rossi Sent: Sat 12/12/2009 10:32 PM To: [email protected] Subject: Re: {SPAM 06.1} [ossec-list] Agents under DHCP This can be worked around using CIDR notation for the address of the agent. Full details can be found here: http://www.ossec.net/wiki/Know_How:DynamicIPs - Jeremy Rossi e: look at the headers people t: http://twitter.com/jrossi On Dec 12, 2009, at 7:00 PM, Dave S wrote: > How does OSSEC handle agents running on systems that are assigned > dynamic addresses? > Specifically, what if a client's address changes from one day to the > next?
