[My apologies for posting this to ossec-dev. I typed in the wrong
google group. This was intended for ossec-list]

All,

I've been trying to write some rules for my lab OSSEC box and test
them before we roll OSSEC out to production. I'm having some problems
writing rules when using the full command. I've tried to follow the
examples written here:
http://www.ossec.net/doc/manual/monitoring/process-monitoring.html

But it seems all my added checks/rules don't work properly.

Basic info:
-Linux - 2.6.18-128.1.6.el5
-OSSEC 2.5.1
-Stand alone server

Here is the example rule I've been trying to get to work...

Check for changes to the system start up services
ossec.conf:
 <localfile>
  <log_format>full_command</log_format>
  <command> /sbin/chkconfig  --list | grep '3:on'</command>
 </localfile>

In local_rules.xml:
 <rule id="510004" level="7">
  <if_sid>530</if_sid>
  <match>ossec: output: ‘/sbin/chkconfig </match>
  <check_diff />
  <description>The system start up services have changed</description>
 </rule>


Upon changing the start up and removing an item I get an alert when
OSSEC notices the start up script file change..It just doesn't seem to
fire off my alert that I have configured.

OSSEC HIDS Notification.
2010 Nov 02 07:16:40
Received From: ossec->syscheck
Rule: 553 fired (level 7) -> "File deleted. Unable to retrieve checksum."
Portion of the log(s):

File '/etc/rc.d/rc0.d/K03yum-updatesd' was deleted. Unable to retrieve checksum.
--END OF NOTIFICATION


Anyone care to tell me what obvious item I'm missing? This holds true
for half a dozen items that I am using full_command for and trying to
check. Another example is below:


Check for changes to the SUID binaries
ossec.conf:
 <localfile>
  <log_format>full_command</log_format>
  <command> find / -user root -perm -4000 -print</command>
 </localfile>

In local_rules.xml:
 <rule id="510005" level="7">
  <if_sid>530</if_sid>
  <match>ossec: output: ‘find / -user root </match>
  <check_diff />
  <description>SUID root binaries have been changed</description>
 </rule>


Thanks for any assistance/input you can provide.
-Tim Eberhard

Reply via email to