[My apologies for posting this to ossec-dev. I typed in the wrong google group. This was intended for ossec-list]
All, I've been trying to write some rules for my lab OSSEC box and test them before we roll OSSEC out to production. I'm having some problems writing rules when using the full command. I've tried to follow the examples written here: http://www.ossec.net/doc/manual/monitoring/process-monitoring.html But it seems all my added checks/rules don't work properly. Basic info: -Linux - 2.6.18-128.1.6.el5 -OSSEC 2.5.1 -Stand alone server Here is the example rule I've been trying to get to work... Check for changes to the system start up services ossec.conf: <localfile> <log_format>full_command</log_format> <command> /sbin/chkconfig --list | grep '3:on'</command> </localfile> In local_rules.xml: <rule id="510004" level="7"> <if_sid>530</if_sid> <match>ossec: output: ‘/sbin/chkconfig </match> <check_diff /> <description>The system start up services have changed</description> </rule> Upon changing the start up and removing an item I get an alert when OSSEC notices the start up script file change..It just doesn't seem to fire off my alert that I have configured. OSSEC HIDS Notification. 2010 Nov 02 07:16:40 Received From: ossec->syscheck Rule: 553 fired (level 7) -> "File deleted. Unable to retrieve checksum." Portion of the log(s): File '/etc/rc.d/rc0.d/K03yum-updatesd' was deleted. Unable to retrieve checksum. --END OF NOTIFICATION Anyone care to tell me what obvious item I'm missing? This holds true for half a dozen items that I am using full_command for and trying to check. Another example is below: Check for changes to the SUID binaries ossec.conf: <localfile> <log_format>full_command</log_format> <command> find / -user root -perm -4000 -print</command> </localfile> In local_rules.xml: <rule id="510005" level="7"> <if_sid>530</if_sid> <match>ossec: output: ‘find / -user root </match> <check_diff /> <description>SUID root binaries have been changed</description> </rule> Thanks for any assistance/input you can provide. -Tim Eberhard
