Building Collector Plugins 1.1 - AlienVault
Building Collector Plugins 1.1 - AlienVault
Building Collector Plugins 1.1 - AlienVault
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
<strong>Building</strong> <strong>Collector</strong> <strong>Plugins</strong> - Admin Guide<br />
[Rule 05 - User Session Closed - IP]<br />
# Jul 14 19:26:25 dmz01 LOGON_EXAMPLE: > ossim pts/2 172.22.22.10 Wed Jul 14 19:26 - 19:26 (00:00)<br />
event_type=event<br />
regexp="^(?P(\S+\s+\d+\s+\d\d:\d\d:\d\d)\s+(?P[^\s]+)\s+LOGON_EXAMPLE:<br />
>\s+(?P[^\s]+)\s+(?P[^\s]+)\s+(?P\IPV4)\s+(?P.*))$"<br />
sensor=\_CFG(plugin-defaults,sensor)<br />
date={normalize_date($1)}<br />
plugin_sid=4<br />
username={$username}<br />
src_ip={$source}<br />
dst_ip={resolv($host)}<br />
userdata1={$tty}<br />
userdata2={md5sum($logline)}<br />
userdata3={$logline}<br />
userdata4={$logged_event}<br />
[Rule 06 - User Session Closed - hostname]<br />
# Jul 14 19:33:56 dmz01 LOGON_EXAMPLE: > root pts/2 localhost Wed Jul 14 19:33 - 19:33 (00:00)<br />
event_type=event<br />
regexp="^(?P(\S+\s+\d+\s+\d\d:\d\d:\d\d)\s+(?P[^\s]+)\s+LOGON_EXAMPLE:<br />
>\s+(?P[^\s]+)\s+(?P[^\s]+)\s+(?Plocalhost)\s+(?P.*))$"<br />
sensor=\_CFG(plugin-defaults,sensor)<br />
date={normalize_date($1)}<br />
plugin_sid=4<br />
username={$username}<br />
src_ip=127.0.0.1<br />
dst_ip={resolv($host)}<br />
userdata1={$tty}<br />
userdata2={md5sum($logline)}<br />
userdata3={$logline}<br />
userdata4={$logged_event}<br />
[Rule 07 - Reboot Detected]<br />
# Jul 14 20:15:09 dmz01 LOGON_EXAMPLE: > reboot system boot 2.6.31.6 Mon May 24 13:51 - 20:15 (51+06:23)<br />
event_type=event<br />
regexp="^(?P(\S+\s+\d+\s+\d\d:\d\d:\d\d)\s+(?P[^\s]+)\s+LOGON_EXAMPLE: >reboot.*))$"<br />
sensor=\_CFG(plugin-defaults,sensor)<br />
date={normalize_date($1)}<br />
plugin_sid=5<br />
userdata1={md5sum($logline)}<br />
userdata2={$logline}<br />
userdata3={$generator}<br />
userdata4={$logged_event}<br />
[Rule 99 - Catch all]<br />
# Whatever doesn't match the above rules<br />
event_type=event<br />
regexp="^(?P(?P\S+\s+\d+\s+\d\d:\d\d:\d\d)\s+(?P[^\s]+)\s+LOGON_EXAMPLE:.*))$"<br />
sensor=\_CFG(plugin-defaults,sensor)<br />
date={normalize_date($date)}<br />
plugin_sid=99<br />
userdata1={md5sum($logline)}<br />
userdata2={$logline}<br />
userdata3={$logged_event}<br />
Page 28 Copyright © Alienvault 2010