The name in the alert should tell you which agent it was. It looks like this
agent's name is dhcp? Make sureto give each system an unique identification
name when adding the agents, and each system should be added with it's own
unique entry.
Sent from my Nokia phone
-----Original Message-----
From: Bryant, Charlie
Sent: 12/13/2009 2:28:01 PM
Subject: Re: {SPAM 06.1} [ossec-list] Agents under DHCP
Or do I even need to install the agent on dhcp workstations? If I create the
a.b.c.0/24 with manage_agents, will it monitor everyone on that subnet?
Thanks,
Charlie
-----Original Message-----
From: Bryant, Charlie
To: [email protected] <[email protected]>
Sent: Sun Dec 13 14:06:23 2009
Subject: RE: {SPAM 06.1} [ossec-list] Agents under DHCP
Just tried this. Cool. And of course, it raises another question.
Here's my first hit from it. It gives the source IP as a.b.c.0. How do I tell
which of my (so far, two) test workstations running the agent from dhcp
addresses fired the rule?
Thanks.
OSSEC HIDS Notification.
2009 Dec 13 13:32:17
Received From: (dhcp) a.b.c.0->rootcheck
Rule: 513 fired (level 9) -> "Windows malware detected."
Portion of the log(s):
Windows Malware: Anti-virus site on the hosts file. File:
C:\WINDOWS\System32\Drivers\etc\HOSTS.
________________________________
From: [email protected] on behalf of Jeremy Rossi
Sent: Sat 12/12/2009 10:32 PM
To: [email protected]
Subject: Re: {SPAM 06.1} [ossec-list] Agents under DHCP
This can be worked around using CIDR notation for the address of the agent.
Full details can be found here: http://www.ossec.net/wiki/Know_How:DynamicIPs
-
Jeremy Rossi
e: look at the headers people
t: http://twitter.com/jrossi
On Dec 12, 2009, at 7:00 PM, Dave S wrote:
> How does OSSEC handle agents running on systems that are assigned
> dynamic addresses?
> Specifically, what if a client's address changes from one day to the
> next?