20.06.2015 Views

Building Collector Plugins 1.1 - AlienVault

Building Collector Plugins 1.1 - AlienVault

Building Collector Plugins 1.1 - AlienVault

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>Building</strong> <strong>Collector</strong> <strong>Plugins</strong> - Admin Guide<br />

o<br />

Normalized Event<br />

There is a certain set of fields which are required in order to ensure a consistent evaluation<br />

and correlation of the events by the OSSIM server. These fields can be populated with<br />

information from the log message or statically through the plug-in.<br />

Example:<br />

ossim-sensor:/var/log/ossim/agent.log:<br />

2010-05-30 13:15:49,441 Output [INFO]: event type="detector" date="1275239752"<br />

sensor="192.168.178.201" interface="eth0" plugin_id="4003" plugin_sid="7"<br />

src_ip="192.168.178.20" src_port="4445" dst_ip="192.168.178.200" dst_port="22"<br />

username="root" log="May 30 13:15:52 dmz01 sshd[12980]: Accepted password for<br />

root from 192.168.178.20 port 4445 ssh2" fdate="2010-05-30 13:15:52" tzone="0"<br />

Page 5 Copyright © Alienvault 2010

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!