官术网_书友最值得收藏!

How to do it...

Now that the server is ready, we'll have to double-check the remote namespace in the /var/ossec/etc/ossec.conf file:

  1. To configure the remote daemon and to communicate with them, we just need to make sure that we implement the following configuration:
    <remote>
         <connection>secure</connection>
         <allowed-ips>192.168.0.0/23</allowed-ips>
    </remote>
  2. Another key setting in server mode is the whitelist for active response. Set it up now as illustrated in the following configuration, even if you don't plan on utilizing the active response:
    <global>
      <!—Our LAN -->
      <white_list>192.168.0.0/23</white_list>
      <!-- MS Exchange Server --> 
      <white_list>1.2.3.4</white_list> 
    </global>
  3. We will then verify and configure our e-mail settings as follows:
      <global>
        <email_notification>yes</email_notification>
        <email_to>security.alerts@example.com</email_to>
        <smtp_server>localhost</smtp_server>
        <email_from>ossecm@server.example.com</email_from>
      </global>
  4. We can then establish our basic e-mail and log thresholds as follows:
      <alerts>
        <log_alert_level>1</log_alert_level>
        <email_alert_level>7</email_alert_level>
      </alerts>
  5. Don't forget to restart the server for the changes to take effect:
    $ sudo /var/ossec/bin/ossec-control restart
    
主站蜘蛛池模板: 喀喇| 老河口市| 饶河县| 广饶县| 昭通市| 广饶县| 化州市| 文化| 广平县| 古田县| 柞水县| 白朗县| 花莲市| 彩票| 德阳市| 黄龙县| 乐至县| 二手房| 友谊县| 乐东| 南皮县| 湄潭县| 大邑县| 海宁市| 长岛县| 佛教| 文安县| 德昌县| 临猗县| 安化县| 松江区| 崇文区| 平邑县| 唐海县| 江门市| 娄烦县| 桐城市| 长白| 泰州市| 麻栗坡县| 双城市|