官术网_书友最值得收藏!

How it works...

The simple configuration options we've specified for our server simply enable the secure communication over the UDP port 1514 between OSSEC clients and the server. We also configured the server to accept connections from our internal networks.

The best practice is to whitelist any IP addresses of potential agents as well as any known external business-critical resources. By whitelisting critical resources, we can ensure that OSSEC never interrupts service to those resources. Any resource that is critical in an emergency should be whitelisted, which is why we have whitelisted the external mail server.

Imagine being under attack and suddenly losing access to e-mail! The last two blocks configure OSSEC to send an e-mail on our network. If we need a specific SMTP server, we can tweak it here. Once we have our e-mail configured, we establish the thresholds for alerting at events whose level is 7 or higher. We will log any events whose level is 1 or higher.

主站蜘蛛池模板: 长葛市| 土默特右旗| 濮阳县| 元氏县| 荆州市| 礼泉县| 南江县| 独山县| 弥渡县| 石家庄市| 平湖市| 日照市| 汶上县| 肇东市| 宜昌市| 巨鹿县| 重庆市| 治县。| 建湖县| 黄梅县| 双辽市| 青浦区| 托里县| 双辽市| 北流市| 太康县| 柏乡县| 茌平县| 鄂尔多斯市| 玛多县| 桃源县| 肃南| 崇义县| 本溪| 通许县| 贡觉县| 西安市| 肥乡县| 阳山县| 汶川县| 弥勒县|