ossim收集linux日志,ossim的日志处理流程

设备把日志信息以syslog的形式发给agent,日志存储在agent上面的/var/log/xxx.log下面,agent调用/etc/ossim/agent/plugins下面对应的xxx插件来/var/log/xxx.log下面取对应的日志,然后根据插件

里面写的正则表达式来提取日志的关键字段发给server,server再将日志分析之后在ossim上面呈

现出来

/etc/ossim/agent/plugins下面的插件,这些是系统自带的还可以自己来编写插件,核心是掌握正则表达式的写法,能够根据不同的日志来提取自己感兴趣的内容。

aladdin.cfg         lucent-brick.cfg        pureftpd.cfg

allot.cfg           m0n0wall.cfg            radiator.cfg

apache.cfg          malwaredomainlist.cfg   raslogd.cfg

arpalert.cfg        mcafee-antispam.cfg     realsecure.cfg

arpwatch.cfg        mcafee.cfg              rrd.cfg

arpwatch_eth0.cfg   modsecurity.cfg         rsa-secureid.cfg

avast.cfg           moodle.cfg              serviceguard.cfg

bind.cfg            motion.cfg              session-monitor.cfg

bro-ids.cfg         mwcollect.cfg           sidewinder.cfg

cisco-acs.cfg       nagios.cfg              siteprotector.cfg

cisco-ids.cfg       nepenthes.cfg           sitescope.cfg

cisco-ips.cfg       nessus-detector.cfg     snare.cfg

cisco-pix.cfg       nessus-monitor.cfg      snort_syslog.cfg

cisco-router.cfg    netgear.cfg             snortunified.cfg

cisco-***.cfg       netscreen-firewall.cfg  snortunified_eth0.cfg

clamav.cfg          netscreen-manager.cfg   sonicwall.cfg

clurgmgr.cfg        netscreen-nsm.cfg       sophos.cfg

courier.cfg         nmap-monitor.cfg        spamassassin.cfg

cyberguard.cfg      nortel-switch.cfg       squid.cfg

dhcp.cfg            ntop-monitor.cfg        squidGuard.cfg

dragon.cfg          ntsyslog.cfg            ssh.cfg

exchange.cfg        ocs-monitor.cfg         stonegate.cfg

f5.cfg              openldap.cfg            sudo.cfg

fidelis.cfg         opennms-monitor.cfg     symantec-ams.cfg

forensics-db-1.cfg  optenet.cfg             symantec-epm.cfg

fortigate.cfg       oracle1.cfg             syslog.cfg

fw1-alt.cfg         oracle.cfg              tarantella.cfg

fw1ngr60.cfg        osiris.cfg              tcptrack-monitor.cfg

gfi.cfg             ossec.cfg               tippingpoint.cfg

heartbeat.cfg       ossim-agent.cfg         topsec.cfg

honeyd.cfg          ossim-monitor.cfg       trendmicro.cfg

hp-eva.cfg          p0f.cfg                 vmware-workstation.cfg

iis.cfg             p0f_eth0.cfg            vsftpd.cfg

intrushield.cfg     pads.cfg                vyatta.cfg

ipfw.cfg            pads_eth0.cfg           webmin.cfg

iphone.cfg          paloalto.cfg            whois-monitor.cfg

iptables.cfg        pam_unix.cfg            wmi-application-logger.cfg

ironport.cfg        panda-as.cfg            wmi-monitor.cfg

isa.cfg             panda-se.cfg            wmi-security-logger.cfg

juniper-***.cfg     pf.cfg                  wmi-system-logger.cfg

kismet.cfg          ping-monitor.cfg

linuxdhcp.cfg       postfix.cfg

要让agent调用某个插件只需要在这个文件里面写上插件的路径就可以了

/etc/ossim/agent/config.cfg 一下展示部分插件的调用:

[plugins]

arpwatch_eth0=/etc/ossim/agent/plugins/arpwatch_eth0.cfg

nmap-monitor=/etc/ossim/agent/plugins/nmap-monitor.cfg

ntop-monitor=/etc/ossim/agent/plugins/ntop-monitor.cfg

oracle=/etc/ossim/agent/plugins/oracle.cfg

ossec=/etc/ossim/agent/plugins/ossec.cfg

ossim-monitor=/etc/ossim/agent/plugins/ossim-monitor.cfg

p0f_eth0=/etc/ossim/agent/plugins/p0f_eth0.cfg

pads_eth0=/etc/ossim/agent/plugins/pads_eth0.cfg

pam_unix=/etc/ossim/agent/plugins/pam_unix.cfg

ping-monitor=/etc/ossim/agent/plugins/ping-monitor.cfg

squid=/etc/ossim/agent/plugins/squid.cfg

ssh=/etc/ossim/agent/plugins/ssh.cfg

sudo=/etc/ossim/agent/plugins/sudo.cfg

whois-monitor=/etc/ossim/agent/plugins/whois-monitor.cfg

wmi-monitor=/etc/ossim/agent/plugins/wmi-monitor.cfg

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值