The name in the alert should tell you which agent it was. It looks like this 
agent's name is dhcp? Make sureto give each system an unique identification 
name when adding the agents, and each system should be added with it's own 
unique entry.

Sent from my Nokia phone
-----Original Message-----
From: Bryant, Charlie
Sent:  12/13/2009 2:28:01 PM
Subject:  Re: {SPAM 06.1} [ossec-list] Agents under DHCP

Or do I even need to install the agent on dhcp workstations?  If I create the 
a.b.c.0/24 with manage_agents, will it monitor everyone on that subnet?


Thanks,

Charlie
 


-----Original Message-----
From: Bryant, Charlie
To: [email protected] <[email protected]>
Sent: Sun Dec 13 14:06:23 2009
Subject: RE: {SPAM 06.1} [ossec-list] Agents under DHCP

Just tried this.  Cool.  And of course, it raises another question.
 
Here's my first hit from it.  It gives the source IP as a.b.c.0.  How do I tell 
which of my (so far, two) test workstations running the agent from dhcp 
addresses fired the rule?  
 
Thanks.
 
 
 
OSSEC HIDS Notification.
2009 Dec 13 13:32:17

Received From: (dhcp) a.b.c.0->rootcheck
Rule: 513 fired (level 9) -> "Windows malware detected."
Portion of the log(s):

Windows Malware: Anti-virus site on the hosts file. File: 
C:\WINDOWS\System32\Drivers\etc\HOSTS.


________________________________

From: [email protected] on behalf of Jeremy Rossi
Sent: Sat 12/12/2009 10:32 PM
To: [email protected]
Subject: Re: {SPAM 06.1} [ossec-list] Agents under DHCP



This can be worked around using CIDR notation for the address of the agent.  
Full details can be found here: http://www.ossec.net/wiki/Know_How:DynamicIPs

-
Jeremy Rossi
e: look at the headers people
t: http://twitter.com/jrossi

On Dec 12, 2009, at 7:00 PM, Dave S wrote:

> How does OSSEC handle agents running on systems that are assigned
> dynamic addresses?
> Specifically, what if a client's address changes from one day to the
> next?




Reply via email to