20.06.2015 Views

Building Collector Plugins 1.1 - AlienVault

Building Collector Plugins 1.1 - AlienVault

Building Collector Plugins 1.1 - AlienVault

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>Building</strong> <strong>Collector</strong> <strong>Plugins</strong> - Admin Guide<br />

[Rule 05 - User Session Closed - IP]<br />

# Jul 14 19:26:25 dmz01 LOGON_EXAMPLE: > ossim pts/2 172.22.22.10 Wed Jul 14 19:26 - 19:26 (00:00)<br />

event_type=event<br />

regexp="^(?P(\S+\s+\d+\s+\d\d:\d\d:\d\d)\s+(?P[^\s]+)\s+LOGON_EXAMPLE:<br />

>\s+(?P[^\s]+)\s+(?P[^\s]+)\s+(?P\IPV4)\s+(?P.*))$"<br />

sensor=\_CFG(plugin-defaults,sensor)<br />

date={normalize_date($1)}<br />

plugin_sid=4<br />

username={$username}<br />

src_ip={$source}<br />

dst_ip={resolv($host)}<br />

userdata1={$tty}<br />

userdata2={md5sum($logline)}<br />

userdata3={$logline}<br />

userdata4={$logged_event}<br />

[Rule 06 - User Session Closed - hostname]<br />

# Jul 14 19:33:56 dmz01 LOGON_EXAMPLE: > root pts/2 localhost Wed Jul 14 19:33 - 19:33 (00:00)<br />

event_type=event<br />

regexp="^(?P(\S+\s+\d+\s+\d\d:\d\d:\d\d)\s+(?P[^\s]+)\s+LOGON_EXAMPLE:<br />

>\s+(?P[^\s]+)\s+(?P[^\s]+)\s+(?Plocalhost)\s+(?P.*))$"<br />

sensor=\_CFG(plugin-defaults,sensor)<br />

date={normalize_date($1)}<br />

plugin_sid=4<br />

username={$username}<br />

src_ip=127.0.0.1<br />

dst_ip={resolv($host)}<br />

userdata1={$tty}<br />

userdata2={md5sum($logline)}<br />

userdata3={$logline}<br />

userdata4={$logged_event}<br />

[Rule 07 - Reboot Detected]<br />

# Jul 14 20:15:09 dmz01 LOGON_EXAMPLE: > reboot system boot 2.6.31.6 Mon May 24 13:51 - 20:15 (51+06:23)<br />

event_type=event<br />

regexp="^(?P(\S+\s+\d+\s+\d\d:\d\d:\d\d)\s+(?P[^\s]+)\s+LOGON_EXAMPLE: >reboot.*))$"<br />

sensor=\_CFG(plugin-defaults,sensor)<br />

date={normalize_date($1)}<br />

plugin_sid=5<br />

userdata1={md5sum($logline)}<br />

userdata2={$logline}<br />

userdata3={$generator}<br />

userdata4={$logged_event}<br />

[Rule 99 - Catch all]<br />

# Whatever doesn't match the above rules<br />

event_type=event<br />

regexp="^(?P(?P\S+\s+\d+\s+\d\d:\d\d:\d\d)\s+(?P[^\s]+)\s+LOGON_EXAMPLE:.*))$"<br />

sensor=\_CFG(plugin-defaults,sensor)<br />

date={normalize_date($date)}<br />

plugin_sid=99<br />

userdata1={md5sum($logline)}<br />

userdata2={$logline}<br />

userdata3={$logged_event}<br />

Page 28 Copyright © Alienvault 2010

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!