20.06.2015 Views

Building Collector Plugins 1.1 - AlienVault

Building Collector Plugins 1.1 - AlienVault

Building Collector Plugins 1.1 - AlienVault

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>Building</strong> <strong>Collector</strong> <strong>Plugins</strong> - Admin Guide<br />

2.2 OSSIM Agent Configuration<br />

2.2.1 Configuration File<br />

/etc/ossim/agent/config.cfg<br />

2.2.2 Parameters<br />

[daemon]<br />

daemon:<br />

pid:<br />

[event-consolidation]<br />

[log]<br />

Daemon mode (True or False)<br />

Path to the PID file (Process identifier)<br />

Enables event consolidation at agent level. It is recommended to use polices instead of this<br />

feature as consolidation at the agent level affects the correlation process.<br />

by_plugin:<br />

enable:<br />

time:<br />

Example:<br />

[event-consolidation]<br />

List of plugins that will be consolidated<br />

Enable or disable (True or False)<br />

Wait n seconds to consolidate the events before sending them<br />

by_plugin=1001-1150,1501-1550,4001-4010<br />

enable=False<br />

time=10<br />

Configures the verbose level and the path to the different log files<br />

error:<br />

file:<br />

stats:<br />

[output-plain]<br />

verbose:<br />

File in which the error events will be stored<br />

File in which all the agent logs will be stored<br />

File in which the agent stats will be stored (Every 5 minutes)<br />

Configures the verbose level (Debug, Info, Warning, Error or<br />

Critical)<br />

Writes in a log file what is being sent to the OSSIM Server (Useful for debugging and<br />

developing purposes)<br />

enable:<br />

file:<br />

[output-server]<br />

Enable or disable (True or False)<br />

File in which the output-plain will be stored<br />

Configures the server to which events are sent<br />

enable:<br />

ip:<br />

port:<br />

Enable or disable sending events to the server (True or False)<br />

IP address of the OSSIM Server<br />

Listening port of the OSSIM Server<br />

Page 11 Copyright © Alienvault 2010

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!