Size: a a a

SOС Технологии

2019 September 06

$

$t3v3;0) in SOС Технологии
hostname ip?
источник

SB

Sergei Bakhaev in SOС Технологии
$t3v3;0)
hostname ip?
По доменному имени.
источник

$

$t3v3;0) in SOС Технологии
Sergei Bakhaev
По доменному имени.
В доке: «Allowed: any valid IP address”
источник

SB

Sergei Bakhaev in SOС Технологии
$t3v3;0)
В доке: «Allowed: any valid IP address”
Оп, упустил. И правда, сейчас попробую.
источник

$

$t3v3;0) in SOС Технологии
Sergei Bakhaev
Оп, упустил. И правда, сейчас попробую.
;)
источник

SB

Sergei Bakhaev in SOС Технологии
Логи пошли, да. Спасибо)
источник

$

$t3v3;0) in SOС Технологии
И в логах кстати как что? /var/ossec/logs/ossec.log
источник

$

$t3v3;0) in SOС Технологии
Через grep syslog
источник

$

$t3v3;0) in SOС Технологии
Если там ошибок не было - значит нужно реквест кидать
источник

$

$t3v3;0) in SOС Технологии
Sergei Bakhaev
Логи пошли, да. Спасибо)
Не за что) ответь на последний вопрос)
источник

SB

Sergei Bakhaev in SOС Технологии
$t3v3;0)
Если там ошибок не было - значит нужно реквест кидать
Неа, никаких ошибок:
2019/09/06 00:00:10 ossec-monitord: INFO: Starting new log after rotation.
2019/09/06 00:00:10 ossec-monitord: INFO: Starting daily reporting for 'Wazuh Daily Report: File changes'
2019/09/06 09:45:36 ossec-monitord: INFO: (1225): SIGNAL [(15)-(Terminated)] Received. Exit Cleaning...
2019/09/06 09:45:36 ossec-logcollector: INFO: (1225): SIGNAL [(15)-(Terminated)] Received. Exit Cleaning...
2019/09/06 09:45:36 ossec-remoted: INFO: (1225): SIGNAL [(15)-(Terminated)] Received. Exit Cleaning...
2019/09/06 09:45:36 ossec-syscheckd: INFO: (1225): SIGNAL [(15)-(Terminated)] Received. Exit Cleaning...
2019/09/06 09:45:37 ossec-analysisd: INFO: (1225): SIGNAL [(15)-(Terminated)] Received. Exit Cleaning...
2019/09/06 09:45:37 ossec-maild: INFO: (1225): SIGNAL [(15)-(Terminated)] Received. Exit Cleaning...
2019/09/06 09:45:37 ossec-execd: INFO: (1314): Shutdown received. Deleting responses.
2019/09/06 09:45:37 ossec-execd: INFO: (1225): SIGNAL [(15)-(Terminated)] Received. Exit Cleaning...
2019/09/06 09:45:37 wazuh-db: INFO: (1225): SIGNAL [(15)-(Terminated)] Received. Exit Cleaning...
2019/09/06 09:45:38 ossec-authd: INFO: (1225): SIGNAL [(15)-(Terminated)] Received. Exit Cleaning...
2019/09/06 09:45:38 ossec-authd: INFO: Exiting...
2019/09/06 09:45:38 ossec-csyslogd: INFO: (1225): SIGNAL [(15)-(Terminated)] Received. Exit Cleaning...
2019/09/06 09:45:39 ossec-csyslogd: INFO: Started (pid: 14429).
2019/09/06 09:45:39 ossec-csyslogd: INFO: Forwarding alerts via syslog to: 'x.x.x.x:514'.
2019/09/06 09:45:39 ossec-dbd: INFO: Database not configured. Clean exit.
2019/09/06 09:45:39 ossec-integratord: INFO: Remote integrations not configured. Clean exit.
2019/09/06 09:45:39 ossec-agentlessd: INFO: Not configured. Exiting.
2019/09/06 09:45:39 ossec-authd: INFO: Started (pid: 14452).
2019/09/06 09:45:39 ossec-authd: INFO: Accepting connections on port 1515. No password required.
2019/09/06 09:45:39 ossec-authd: INFO: Setting network timeout to 1.000000 sec.
2019/09/06 09:45:39 wazuh-db: INFO: Started (pid: 14461).
2019/09/06 09:45:39 ossec-execd: INFO: (1350): Active response disabled.
2019/09/06 09:45:39 ossec-execd: INFO: Started (pid: 14480).
2019/09/06 09:45:39 ossec-maild: INFO: Started (pid: 14488).
2019/09/06 09:45:39 ossec-maild: INFO: Getting alerts in JSON format.
2019/09/06 09:45:39 ossec-syscheckd: INFO: (6678): No directory provided for syscheck to monitor.
2019/09/06 09:45:39 ossec-syscheckd: INFO: (6001): File integrity monitoring disabled.
2019/09/06 09:45:39 rootcheck: INFO: Rootcheck disabled.
2019/09/06 09:45:39 ossec-remoted: INFO: Started (pid: 14509). Listening on port 1514/TCP (secure).
2019/09/06 09:45:39 ossec-monitord: INFO: Started (pid: 14538).
2019/09/06 09:45:39 wazuh-modulesd: INFO: Process started.
2019/09/06 09:45:39 sca: INFO: Module disabled. Exiting.
2019/09/06 09:45:39 wazuh-modulesd:database: INFO: Module started.
2019/09/06 09:45:39 wazuh-modulesd:download: INFO: Module started
2019/09/06 09:45:40 ossec-analysisd: INFO: Total rules enabled: '3395'
2019/09/06 09:45:40 ossec-analysisd: INFO: Started (pid: 14493).
2019/09/06 09:45:40 ossec-logcollector: INFO: (1950): Analyzing file: '/var/log/syslog'.
2019/09/06 09:45:40 ossec-logcollector: INFO: (1950): Analyzing file: '/var/log/auth.log'.
2019/09/06 09:45:40 ossec-logcollector: INFO: (1950): Analyzing file: '/var/log/dpkg.log'.
2019/09/06 09:45:40 ossec-logcollector: INFO: (1950): Analyzing file: '/var/log/kern.log'.
2019/09/06 09:45:40 ossec-logcollector: INFO: (1950): Analyzing file: '/var/ossec/logs/ossec.log'.
2019/09/06 09:45:40 ossec-logcollector: INFO: Started (pid: 14513).
2019/09/06 09:45:40 ossec-remoted: INFO: (4111): Maximum number of agents allowed: '14000'.
2019/09/06 09:45:40 ossec-remoted: INFO: (1410): Reading authentication keys file.
источник

$

$t3v3;0) in SOС Технологии
Sergei Bakhaev
Неа, никаких ошибок:
2019/09/06 00:00:10 ossec-monitord: INFO: Starting new log after rotation.
2019/09/06 00:00:10 ossec-monitord: INFO: Starting daily reporting for 'Wazuh Daily Report: File changes'
2019/09/06 09:45:36 ossec-monitord: INFO: (1225): SIGNAL [(15)-(Terminated)] Received. Exit Cleaning...
2019/09/06 09:45:36 ossec-logcollector: INFO: (1225): SIGNAL [(15)-(Terminated)] Received. Exit Cleaning...
2019/09/06 09:45:36 ossec-remoted: INFO: (1225): SIGNAL [(15)-(Terminated)] Received. Exit Cleaning...
2019/09/06 09:45:36 ossec-syscheckd: INFO: (1225): SIGNAL [(15)-(Terminated)] Received. Exit Cleaning...
2019/09/06 09:45:37 ossec-analysisd: INFO: (1225): SIGNAL [(15)-(Terminated)] Received. Exit Cleaning...
2019/09/06 09:45:37 ossec-maild: INFO: (1225): SIGNAL [(15)-(Terminated)] Received. Exit Cleaning...
2019/09/06 09:45:37 ossec-execd: INFO: (1314): Shutdown received. Deleting responses.
2019/09/06 09:45:37 ossec-execd: INFO: (1225): SIGNAL [(15)-(Terminated)] Received. Exit Cleaning...
2019/09/06 09:45:37 wazuh-db: INFO: (1225): SIGNAL [(15)-(Terminated)] Received. Exit Cleaning...
2019/09/06 09:45:38 ossec-authd: INFO: (1225): SIGNAL [(15)-(Terminated)] Received. Exit Cleaning...
2019/09/06 09:45:38 ossec-authd: INFO: Exiting...
2019/09/06 09:45:38 ossec-csyslogd: INFO: (1225): SIGNAL [(15)-(Terminated)] Received. Exit Cleaning...
2019/09/06 09:45:39 ossec-csyslogd: INFO: Started (pid: 14429).
2019/09/06 09:45:39 ossec-csyslogd: INFO: Forwarding alerts via syslog to: 'x.x.x.x:514'.
2019/09/06 09:45:39 ossec-dbd: INFO: Database not configured. Clean exit.
2019/09/06 09:45:39 ossec-integratord: INFO: Remote integrations not configured. Clean exit.
2019/09/06 09:45:39 ossec-agentlessd: INFO: Not configured. Exiting.
2019/09/06 09:45:39 ossec-authd: INFO: Started (pid: 14452).
2019/09/06 09:45:39 ossec-authd: INFO: Accepting connections on port 1515. No password required.
2019/09/06 09:45:39 ossec-authd: INFO: Setting network timeout to 1.000000 sec.
2019/09/06 09:45:39 wazuh-db: INFO: Started (pid: 14461).
2019/09/06 09:45:39 ossec-execd: INFO: (1350): Active response disabled.
2019/09/06 09:45:39 ossec-execd: INFO: Started (pid: 14480).
2019/09/06 09:45:39 ossec-maild: INFO: Started (pid: 14488).
2019/09/06 09:45:39 ossec-maild: INFO: Getting alerts in JSON format.
2019/09/06 09:45:39 ossec-syscheckd: INFO: (6678): No directory provided for syscheck to monitor.
2019/09/06 09:45:39 ossec-syscheckd: INFO: (6001): File integrity monitoring disabled.
2019/09/06 09:45:39 rootcheck: INFO: Rootcheck disabled.
2019/09/06 09:45:39 ossec-remoted: INFO: Started (pid: 14509). Listening on port 1514/TCP (secure).
2019/09/06 09:45:39 ossec-monitord: INFO: Started (pid: 14538).
2019/09/06 09:45:39 wazuh-modulesd: INFO: Process started.
2019/09/06 09:45:39 sca: INFO: Module disabled. Exiting.
2019/09/06 09:45:39 wazuh-modulesd:database: INFO: Module started.
2019/09/06 09:45:39 wazuh-modulesd:download: INFO: Module started
2019/09/06 09:45:40 ossec-analysisd: INFO: Total rules enabled: '3395'
2019/09/06 09:45:40 ossec-analysisd: INFO: Started (pid: 14493).
2019/09/06 09:45:40 ossec-logcollector: INFO: (1950): Analyzing file: '/var/log/syslog'.
2019/09/06 09:45:40 ossec-logcollector: INFO: (1950): Analyzing file: '/var/log/auth.log'.
2019/09/06 09:45:40 ossec-logcollector: INFO: (1950): Analyzing file: '/var/log/dpkg.log'.
2019/09/06 09:45:40 ossec-logcollector: INFO: (1950): Analyzing file: '/var/log/kern.log'.
2019/09/06 09:45:40 ossec-logcollector: INFO: (1950): Analyzing file: '/var/ossec/logs/ossec.log'.
2019/09/06 09:45:40 ossec-logcollector: INFO: Started (pid: 14513).
2019/09/06 09:45:40 ossec-remoted: INFO: (4111): Maximum number of agents allowed: '14000'.
2019/09/06 09:45:40 ossec-remoted: INFO: (1410): Reading authentication keys file.
Это у тебя уже ротация прошла при перезапуске
источник

$

$t3v3;0) in SOС Технологии
Sergei Bakhaev
Оп, упустил. И правда, сейчас попробую.
Вот после этого
источник

SB

Sergei Bakhaev in SOС Технологии
$t3v3;0)
Вот после этого
Да, но пока я не прописал новый конфиг в 9:45, должны же были быть ошибки? Он же должен был за всю ночь хоть раз постучаться по syslog?
источник

SB

Sergei Bakhaev in SOС Технологии
Sergei Bakhaev
Да, но пока я не прописал новый конфиг в 9:45, должны же были быть ошибки? Он же должен был за всю ночь хоть раз постучаться по syslog?
За вчера в логах вообще три строчки:
2019/09/05 00:00:10 ossec-monitord: INFO: Starting new log after rotation.
2019/09/05 00:00:10 ossec-monitord: INFO: Starting daily reporting for 'Wazuh Daily Report: File changes'
2019/09/06 00:00:10 ossec-monitord: INFO: Running daily rotation of log files.
источник

$

$t3v3;0) in SOС Технологии
Забавно, нужно поставить поиграться, видимо
источник

D

Dmitry Artamonov in SOС Технологии
сорян, не то :)
источник
2019 September 12

DP

D P in SOС Технологии
Товарищи, а есть угорающие по elastalert? -)
источник

DP

D P in SOС Технологии
В правиле frequency compound query_key вообще работает? По документам типа да, а де-факто как-то нет.
источник

SS

Sergey Soldatov in SOС Технологии
D P
Товарищи, а есть угорающие по elastalert? -)
штатный watcher из x-pack прекрасно работает
источник