20.06.2015 Views

Building Collector Plugins 1.1 - AlienVault

Building Collector Plugins 1.1 - AlienVault

Building Collector Plugins 1.1 - AlienVault

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Building</strong> <strong>Collector</strong> <strong>Plugins</strong> - Admin Guide<br />

2.7.2 Structure ................................................................................................................................... 19<br />

2.8 Loading <strong>Plugins</strong> ................................................................................................................................. 21<br />

2.8.1 Priority and Reliability values ................................................................................................... 21<br />

2.8.2 SQL Statement .......................................................................................................................... 21<br />

2.9 Plugin Activation ............................................................................................................................... 22<br />

2.9.1 Activate the Plugin on the Server Side ..................................................................................... 22<br />

2.9.2 Activate the Plugin on the Agent Side ...................................................................................... 22<br />

3 Log files ..................................................................................................................................................... 22<br />

4 Debugging ................................................................................................................................................. 22<br />

5 Appendix ................................................................................................................................................... 23<br />

5.1 Regular Expressions .......................................................................................................................... 23<br />

5.2 Configuration Example ..................................................................................................................... 25<br />

5.2.1 Scenario .................................................................................................................................... 25<br />

5.2.2 Write a script to monitor the “last” status ............................................................................... 25<br />

5.2.3 Log sample ................................................................................................................................ 25<br />

5.2.4 Collect the logs in a new log file ............................................................................................... 25<br />

5.2.5 Restart “rsyslog”....................................................................................................................... 26<br />

5.2.6 Check whether the new entries are written in the new log file ............................................... 26<br />

5.2.7 Create a plugin file .................................................................................................................... 26<br />

5.2.8 Register the Plugin with the OSSIM Agent ............................................................................... 29<br />

5.2.9 Register the Plugin with the OSSIM Server .............................................................................. 30<br />

5.2.10 Check whether the plugin was successfully registered ............................................................ 31<br />

5.2.11 Restart the OSSIM Server ......................................................................................................... 31<br />

5.2.12 Restart the OSSIM Agent .......................................................................................................... 31<br />

5.2.13 Check whether Events and Alarms are received ...................................................................... 32<br />

Page 3 Copyright © Alienvault 2010

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!