官术网_书友最值得收藏!

How to do it...

Now that the server is ready, we'll have to double-check the remote namespace in the /var/ossec/etc/ossec.conf file:

  1. To configure the remote daemon and to communicate with them, we just need to make sure that we implement the following configuration:
    <remote>
         <connection>secure</connection>
         <allowed-ips>192.168.0.0/23</allowed-ips>
    </remote>
  2. Another key setting in server mode is the whitelist for active response. Set it up now as illustrated in the following configuration, even if you don't plan on utilizing the active response:
    <global>
      <!—Our LAN -->
      <white_list>192.168.0.0/23</white_list>
      <!-- MS Exchange Server --> 
      <white_list>1.2.3.4</white_list> 
    </global>
  3. We will then verify and configure our e-mail settings as follows:
      <global>
        <email_notification>yes</email_notification>
        <email_to>security.alerts@example.com</email_to>
        <smtp_server>localhost</smtp_server>
        <email_from>ossecm@server.example.com</email_from>
      </global>
  4. We can then establish our basic e-mail and log thresholds as follows:
      <alerts>
        <log_alert_level>1</log_alert_level>
        <email_alert_level>7</email_alert_level>
      </alerts>
  5. Don't forget to restart the server for the changes to take effect:
    $ sudo /var/ossec/bin/ossec-control restart
    
主站蜘蛛池模板: 鸡泽县| 南川市| 山东省| 南陵县| 多伦县| 年辖:市辖区| 嵩明县| 赤城县| 珠海市| 扎囊县| 镶黄旗| 大丰市| 伊川县| 色达县| 渝中区| 富顺县| 祁连县| 湾仔区| 封丘县| 桐梓县| 五峰| 观塘区| 仲巴县| 杂多县| 天柱县| 巩义市| 古交市| SHOW| 科技| 德令哈市| 绥阳县| 进贤县| 武邑县| 石首市| 汶川县| 会同县| 大兴区| 丹寨县| 富裕县| 华阴市| 湘潭县|