20.06.2015 Views

Building Collector Plugins 1.1 - AlienVault

Building Collector Plugins 1.1 - AlienVault

Building Collector Plugins 1.1 - AlienVault

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Building</strong> <strong>Collector</strong> <strong>Plugins</strong> - Admin Guide<br />

date={normalize_date($1)}<br />

plugin_sid=1<br />

username={$username}<br />

dst_ip={resolv($host)}<br />

userdata1={$tty}<br />

userdata2={md5sum($logline)}<br />

userdata3={$logline}<br />

userdata4={$logged_event}<br />

[Rule 02 - Console Session Closed]<br />

# Jul 14 20:35:46 dmz01 LOGON_EXAMPLE: > root tty1 Wed Jul 14 20:18 - 20:35 (00:17)<br />

event_type=event<br />

regexp="^(?P(\S+\s+\d+\s+\d\d:\d\d:\d\d)\s+(?P[^\s]+)\s+LOGON_EXAMPLE:<br />

>\s+(?P[^\s]+)\s+(?Ptty\d+)\s+(?P.*))$"<br />

sensor=\_CFG(plugin-defaults,sensor)<br />

date={normalize_date($1)}<br />

plugin_sid=2<br />

username={$username}<br />

dst_ip={resolv($host)}<br />

userdata1={$tty}<br />

userdata2={md5sum($logline)}<br />

userdata3={$logline}<br />

userdata4={$logged_event}<br />

[Rule 03 - New User Session - IP]<br />

# Jul 14 20:21:49 dmz01 LOGON_EXAMPLE: > root pts/1 172.22.22.10 Wed Jul 14 20:21 still logged in<br />

event_type=event<br />

regexp="^(?P(\S+\s+\d+\s+\d\d:\d\d:\d\d)\s+(?P[^\s]+)\s+LOGON_EXAMPLE:<br />

>\s+(?P[^\s]+)\s+(?P[^\s]+)\s+(?P\IPV4)\s+(?P.*still logged in.*))$"<br />

sensor=\_CFG(plugin-defaults,sensor)<br />

date={normalize_date($1)}<br />

plugin_sid=3<br />

username={$username}<br />

src_ip={$source}<br />

dst_ip={resolv($host)}<br />

userdata1={$tty}<br />

userdata2={md5sum($logline)}<br />

userdata3={$logline}<br />

userdata4={$logged_event}<br />

[Rule 04 - New User Session - hostname]<br />

# Jul 14 19:23:28 dmz01 LOGON_EXAMPLE: > dbadmin pts/3 localhost Wed Jul 14 19:23 still logged in<br />

event_type=event<br />

regexp="^(?P(\S+\s+\d+\s+\d\d:\d\d:\d\d)\s+(?P[^\s]+)\s+LOGON_EXAMPLE:<br />

>\s+(?P[^\s]+)\s+(?P[^\s]+)\s+(?Plocalhost)\s+(?P.*still logged in.*))$"<br />

sensor=\_CFG(plugin-defaults,sensor)<br />

date={normalize_date($1)}<br />

plugin_sid=3<br />

username={$username}<br />

src_ip=127.0.0.1<br />

dst_ip={resolv($host)}<br />

userdata1={$tty}<br />

userdata2={md5sum($logline)}<br />

userdata3={$logline}<br />

userdata4={$logged_event}<br />

Page 27 Copyright © Alienvault 2010

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!