OSSEC installation guide

本文指导您如何下载、安装和配置OSSEC入侵检测系统,包括在服务器主机上安装服务器,在客户端主机上安装代理,以及进行基本的管理操作。解决安装过程中遇到的常见问题,并提供简单命令示例来检查状态、查看日志、启动或停止OSSEC服务。

摘要生成于 C知道 ,由 DeepSeek-R1 满血版支持, 前往体验 >

SSEC is an Open Source Host-based Intrusion Detection System. It performs log analysis, integrity checking, Windows registry monitoring, rootkit detection, real-time alerting and active response. It runs on most operating systems, including Linux, OpenBSD, FreeBSD, Mac OS X, Solaris and Windows.

The official document link: http://www.ossec.net/doc/index.html


How to install OSSEC

  1. Download the latest version
    #wget http://www.ossec.net/files/ossec-hids-2.7.1-beta-1.tar.gz


  2. Extract the compressed package and run the “./install.sh” script (It will guide you through the installation).
    # tar -zxvf ossec-hids-*.tar.gz (or gunzip -d; tar -xvf)
    # cd ossec-hids-*
    # ./install.sh


  3. Follow the installation prompts and complete all steps.
    Install Server on server host.
    Install Agent on client host.


The configuration part

Add client agent into Server host.

  • On server machine type command. 
    #/var/ossec/bin/manage_agents
  • Select "A" to enter into add agent menu, and input the agent name and IP.
  • Back to main menu and select "E" option for extract key for client agent.
  • Copy the Key to somewhere save for agent machine.
  • On agent machine side. 
    #/var/ossec/bin/manage_agents
  • Select "I" option for import the key which just extracted from server machine.

You are all set now!


Some simple command examples.

  1. Check the status of your agents
    #/var/ossec/bin/agent_control -lc
    or
    #/var/ossec/bin/agent_control -i agentID

  2. Check the latest log status
    # tail -F /var/ossec/logs/ossec.log

  3. Start/Stop OSSEC process
    #/var/ossec/bin/ossec-control start/stop

  4. Manage agent main menu
    #/var/ossec/bin/manage_agents

Issues:
There is a bug in official build 2.7 that the agents disconnect after a few minutes.  for resolve it, you may need to upgrade to version 2.7.1 beta.


评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值