Building Collector Plugins 1.1 - AlienVault
Building Collector Plugins 1.1 - AlienVault
Building Collector Plugins 1.1 - AlienVault
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
<strong>Building</strong> <strong>Collector</strong> <strong>Plugins</strong> - Admin Guide<br />
2.2 OSSIM Agent Configuration<br />
2.2.1 Configuration File<br />
/etc/ossim/agent/config.cfg<br />
2.2.2 Parameters<br />
[daemon]<br />
daemon:<br />
pid:<br />
[event-consolidation]<br />
[log]<br />
Daemon mode (True or False)<br />
Path to the PID file (Process identifier)<br />
Enables event consolidation at agent level. It is recommended to use polices instead of this<br />
feature as consolidation at the agent level affects the correlation process.<br />
by_plugin:<br />
enable:<br />
time:<br />
Example:<br />
[event-consolidation]<br />
List of plugins that will be consolidated<br />
Enable or disable (True or False)<br />
Wait n seconds to consolidate the events before sending them<br />
by_plugin=1001-1150,1501-1550,4001-4010<br />
enable=False<br />
time=10<br />
Configures the verbose level and the path to the different log files<br />
error:<br />
file:<br />
stats:<br />
[output-plain]<br />
verbose:<br />
File in which the error events will be stored<br />
File in which all the agent logs will be stored<br />
File in which the agent stats will be stored (Every 5 minutes)<br />
Configures the verbose level (Debug, Info, Warning, Error or<br />
Critical)<br />
Writes in a log file what is being sent to the OSSIM Server (Useful for debugging and<br />
developing purposes)<br />
enable:<br />
file:<br />
[output-server]<br />
Enable or disable (True or False)<br />
File in which the output-plain will be stored<br />
Configures the server to which events are sent<br />
enable:<br />
ip:<br />
port:<br />
Enable or disable sending events to the server (True or False)<br />
IP address of the OSSIM Server<br />
Listening port of the OSSIM Server<br />
Page 11 Copyright © Alienvault 2010