Building Collector Plugins 1.1 - AlienVault
Building Collector Plugins 1.1 - AlienVault
Building Collector Plugins 1.1 - AlienVault
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
<strong>Building</strong> <strong>Collector</strong> <strong>Plugins</strong> - Admin Guide<br />
date={normalize_date($1)}<br />
plugin_sid=1<br />
username={$username}<br />
dst_ip={resolv($host)}<br />
userdata1={$tty}<br />
userdata2={md5sum($logline)}<br />
userdata3={$logline}<br />
userdata4={$logged_event}<br />
[Rule 02 - Console Session Closed]<br />
# Jul 14 20:35:46 dmz01 LOGON_EXAMPLE: > root tty1 Wed Jul 14 20:18 - 20:35 (00:17)<br />
event_type=event<br />
regexp="^(?P(\S+\s+\d+\s+\d\d:\d\d:\d\d)\s+(?P[^\s]+)\s+LOGON_EXAMPLE:<br />
>\s+(?P[^\s]+)\s+(?Ptty\d+)\s+(?P.*))$"<br />
sensor=\_CFG(plugin-defaults,sensor)<br />
date={normalize_date($1)}<br />
plugin_sid=2<br />
username={$username}<br />
dst_ip={resolv($host)}<br />
userdata1={$tty}<br />
userdata2={md5sum($logline)}<br />
userdata3={$logline}<br />
userdata4={$logged_event}<br />
[Rule 03 - New User Session - IP]<br />
# Jul 14 20:21:49 dmz01 LOGON_EXAMPLE: > root pts/1 172.22.22.10 Wed Jul 14 20:21 still logged in<br />
event_type=event<br />
regexp="^(?P(\S+\s+\d+\s+\d\d:\d\d:\d\d)\s+(?P[^\s]+)\s+LOGON_EXAMPLE:<br />
>\s+(?P[^\s]+)\s+(?P[^\s]+)\s+(?P\IPV4)\s+(?P.*still logged in.*))$"<br />
sensor=\_CFG(plugin-defaults,sensor)<br />
date={normalize_date($1)}<br />
plugin_sid=3<br />
username={$username}<br />
src_ip={$source}<br />
dst_ip={resolv($host)}<br />
userdata1={$tty}<br />
userdata2={md5sum($logline)}<br />
userdata3={$logline}<br />
userdata4={$logged_event}<br />
[Rule 04 - New User Session - hostname]<br />
# Jul 14 19:23:28 dmz01 LOGON_EXAMPLE: > dbadmin pts/3 localhost Wed Jul 14 19:23 still logged in<br />
event_type=event<br />
regexp="^(?P(\S+\s+\d+\s+\d\d:\d\d:\d\d)\s+(?P[^\s]+)\s+LOGON_EXAMPLE:<br />
>\s+(?P[^\s]+)\s+(?P[^\s]+)\s+(?Plocalhost)\s+(?P.*still logged in.*))$"<br />
sensor=\_CFG(plugin-defaults,sensor)<br />
date={normalize_date($1)}<br />
plugin_sid=3<br />
username={$username}<br />
src_ip=127.0.0.1<br />
dst_ip={resolv($host)}<br />
userdata1={$tty}<br />
userdata2={md5sum($logline)}<br />
userdata3={$logline}<br />
userdata4={$logged_event}<br />
Page 27 Copyright © Alienvault 2010