Building Collector Plugins 1.1 - AlienVault
Building Collector Plugins 1.1 - AlienVault
Building Collector Plugins 1.1 - AlienVault
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
<strong>Building</strong> <strong>Collector</strong> <strong>Plugins</strong> - Admin Guide<br />
o<br />
Normalized Event<br />
There is a certain set of fields which are required in order to ensure a consistent evaluation<br />
and correlation of the events by the OSSIM server. These fields can be populated with<br />
information from the log message or statically through the plug-in.<br />
Example:<br />
ossim-sensor:/var/log/ossim/agent.log:<br />
2010-05-30 13:15:49,441 Output [INFO]: event type="detector" date="1275239752"<br />
sensor="192.168.178.201" interface="eth0" plugin_id="4003" plugin_sid="7"<br />
src_ip="192.168.178.20" src_port="4445" dst_ip="192.168.178.200" dst_port="22"<br />
username="root" log="May 30 13:15:52 dmz01 sshd[12980]: Accepted password for<br />
root from 192.168.178.20 port 4445 ssh2" fdate="2010-05-30 13:15:52" tzone="0"<br />
Page 5 Copyright © Alienvault 2010