On Tue, Nov 2, 2010 at 4:13 PM, Tim Eberhard <[email protected]> wrote: > [My apologies for posting this to ossec-dev. I typed in the wrong > google group. This was intended for ossec-list] > > All, > > I've been trying to write some rules for my lab OSSEC box and test > them before we roll OSSEC out to production. I'm having some problems > writing rules when using the full command. I've tried to follow the > examples written here: > http://www.ossec.net/doc/manual/monitoring/process-monitoring.html > > But it seems all my added checks/rules don't work properly. > > Basic info: > -Linux - 2.6.18-128.1.6.el5 > -OSSEC 2.5.1 > -Stand alone server > > Here is the example rule I've been trying to get to work... > > Check for changes to the system start up services > ossec.conf: > <localfile> > <log_format>full_command</log_format> > <command> /sbin/chkconfig --list | grep '3:on'</command>
Is the space in the <command> above intentional or a paste-o? I don't know if it will affect the output or not... > </localfile> > > In local_rules.xml: > <rule id="510004" level="7"> > <if_sid>530</if_sid> > <match>ossec: output: ‘/sbin/chkconfig </match> > <check_diff /> > <description>The system start up services have changed</description> > </rule> > > > Upon changing the start up and removing an item I get an alert when > OSSEC notices the start up script file change..It just doesn't seem to > fire off my alert that I have configured. > > OSSEC HIDS Notification. > 2010 Nov 02 07:16:40 > Received From: ossec->syscheck > Rule: 553 fired (level 7) -> "File deleted. Unable to retrieve checksum." > Portion of the log(s): > > File '/etc/rc.d/rc0.d/K03yum-updatesd' was deleted. Unable to retrieve > checksum. > --END OF NOTIFICATION > > > Anyone care to tell me what obvious item I'm missing? This holds true > for half a dozen items that I am using full_command for and trying to > check. Another example is below: > > > Check for changes to the SUID binaries > ossec.conf: > <localfile> > <log_format>full_command</log_format> > <command> find / -user root -perm -4000 -print</command> > </localfile> > > In local_rules.xml: > <rule id="510005" level="7"> > <if_sid>530</if_sid> > <match>ossec: output: ‘find / -user root </match> > <check_diff /> > <description>SUID root binaries have been changed</description> > </rule> > > > Thanks for any assistance/input you can provide. > -Tim Eberhard >
