Rules management

by Meir Michanie

meirm ( at ) riunx dot com

OSSEC rules management Mini Howto

Install base

Install ossec2base

Build signature files for BASE

/var/ossec# mkdir -p /var/www/html/ossecbase/signatures/


/var/ossec# cat rules/*.xml | perl contrib/ossec2basetxt.pl -e -o /var/www/html/ossecbase/signatures/


Initialize OSSEC BASE database (optional)

/var/ossec# echo 'TRUNCATE TABLE `signature` ;' | mysql ossecbase -p

/var/ossec# echo 'TRUNCATE TABLE `sensor` ;' | mysql ossecbase -p

/var/ossec# echo 'TRUNCATE TABLE `acid_event` ;' | mysql ossecbase -p
/var/ossec# echo 'TRUNCATE TABLE `events` ;' | mysql ossecbase -p
/var/ossec# echo 'TRUNCATE TABLE `data` ;' | mysql ossecbase -p


Run manual feed of events

zcat /var/ossec/logs/alerts/2006/Jul/ossec-alerts-31.log.gz|  /home/meirm/ossec/cvs/ossec-ui/base/bin/ossec2base.pl --conf /etc/ossec2base.conf --interface manualfeed


Run Real time feed of events

/usr/local/bin/ossec2based.pl --conf /etc/ossec2base.conf -d --sensor bigbrother

Enjoy Ossec2Base

$ firefox http://localhost/ossecbase