3 ms·
I'd propose using OSSEC over logwatch & fail2ban. Ossec seems to be a bit of an obscure tool, but a thoroughly functional one at that. Logwatch gives a bit too
by matwizzle 14y ago
I'd propose using OSSEC over logwatch & fail2ban. Ossec seems to be a bit of an obscure tool, but a thoroughly functional one at that. Logwatch gives a bit too much info at once to interpret properly, while OSSEC will only alert you when something is actually up.
Ossec provides (among some other things):
* Log file monitoring, with severity levels, occurence counting, time-based rules and auto-response. This means (for instance) you get to watch your auth.log for failed login attempts and after 10 failures fire a script to ban him, alert sysop by email or have hubot alert your sysops. Or whatever floats your boat.
* File integrity monitoring. Make sure noone's been mucking around with your files. It has real-time support (through inotify), but if you don't want use that, make sure you store the database it keeps off-server for forensics if need be. Pro-tip: FIM and auto-updates are a tad unnerving.
* It can watch command output. You can use that to make sure the `netstat -tnap` output doesn't change, for instance.
* For larger/more compliant instances, it has a client<->server setup available.
- daemon13 14y agoI have heard good words about OSSEC but never tried it because of it's perception being: - heavyweight; - not actively developed. Are my perceptions right? If no, how would you recommend to start using it? Any good tutorials or other pointers?
- matwizzle 14y agoLast version dates from 2012-11-19, not the fastest of releases - but seems ok. Trend Micro is involved (and offers commercial support). It doesn't feel heavyweight to me. It does start a bunch of daemons for all of its processing and it has the client->server bit built right in. That may make it feel heavyweight, I guess. But, you don't have to use the client->server stuff if you don't want to. It'll still do all of its magic for you. Ossec will do a lot out of the box. So, I suggest installing it with the default ruleset and the active-response stuff turned off (the installer will ask you). Then dive into the rules and ossec.conf (knowledge of regex is required). Documentation @ http://www.ossec.net/doc/index.html http://www.ossec.net/doc/index.html
- druiid 14y agoOssec is actively developed. They just had a new release a few months ago. Realistically it doesn't get updated as much as it used to, but it still is actively developed. I think more than anything it is just kind of at a near end-state where there isn't a whole lot left to ADD other than some signature type updates, or nice-to-have features. It is a program that I HIGHLY recommend having and it is very simple to get up and running, even if you don't have packages of it for your OS version. Also you won't pass PCI-1 without a IDS like this.