Or do I even need to install the agent on dhcp workstations?  If I create the 
a.b.c.0/24 with manage_agents, will it monitor everyone on that subnet?


Thanks,

Charlie
 


-----Original Message-----
From: Bryant, Charlie
To: [email protected] <[email protected]>
Sent: Sun Dec 13 14:06:23 2009
Subject: RE: {SPAM 06.1} [ossec-list] Agents under DHCP

Just tried this.  Cool.  And of course, it raises another question.
 
Here's my first hit from it.  It gives the source IP as a.b.c.0.  How do I tell 
which of my (so far, two) test workstations running the agent from dhcp 
addresses fired the rule?  
 
Thanks.
 
 
 
OSSEC HIDS Notification.
2009 Dec 13 13:32:17

Received From: (dhcp) a.b.c.0->rootcheck
Rule: 513 fired (level 9) -> "Windows malware detected."
Portion of the log(s):

Windows Malware: Anti-virus site on the hosts file. File: 
C:\WINDOWS\System32\Drivers\etc\HOSTS.


________________________________

From: [email protected] on behalf of Jeremy Rossi
Sent: Sat 12/12/2009 10:32 PM
To: [email protected]
Subject: Re: {SPAM 06.1} [ossec-list] Agents under DHCP



This can be worked around using CIDR notation for the address of the agent.  
Full details can be found here: http://www.ossec.net/wiki/Know_How:DynamicIPs

-
Jeremy Rossi
e: look at the headers people
t: http://twitter.com/jrossi

On Dec 12, 2009, at 7:00 PM, Dave S wrote:

> How does OSSEC handle agents running on systems that are assigned
> dynamic addresses?
> Specifically, what if a client's address changes from one day to the
> next?



Reply via email to