官术网_书友最值得收藏!

How it works...

The simple configuration options we've specified for our server simply enable the secure communication over the UDP port 1514 between OSSEC clients and the server. We also configured the server to accept connections from our internal networks.

The best practice is to whitelist any IP addresses of potential agents as well as any known external business-critical resources. By whitelisting critical resources, we can ensure that OSSEC never interrupts service to those resources. Any resource that is critical in an emergency should be whitelisted, which is why we have whitelisted the external mail server.

Imagine being under attack and suddenly losing access to e-mail! The last two blocks configure OSSEC to send an e-mail on our network. If we need a specific SMTP server, we can tweak it here. Once we have our e-mail configured, we establish the thresholds for alerting at events whose level is 7 or higher. We will log any events whose level is 1 or higher.

主站蜘蛛池模板: 慈利县| 阿巴嘎旗| 江陵县| 双柏县| 乐至县| 张家界市| 铜山县| 黄山市| 新竹市| 泽库县| 罗田县| 扬州市| 大化| 内黄县| 南和县| 青川县| 太仓市| 枝江市| 苏尼特右旗| 岳普湖县| 双峰县| 新河县| 蛟河市| 灵川县| 尼木县| 澳门| 衡阳市| 信丰县| 乐山市| 崇仁县| 河源市| 晋宁县| 体育| 喀什市| 大宁县| 怀远县| 景德镇市| 南丰县| 平潭县| 泗洪县| 巴彦县|