官术网_书友最值得收藏!

How it works...

The simple configuration options we've specified for our server simply enable the secure communication over the UDP port 1514 between OSSEC clients and the server. We also configured the server to accept connections from our internal networks.

The best practice is to whitelist any IP addresses of potential agents as well as any known external business-critical resources. By whitelisting critical resources, we can ensure that OSSEC never interrupts service to those resources. Any resource that is critical in an emergency should be whitelisted, which is why we have whitelisted the external mail server.

Imagine being under attack and suddenly losing access to e-mail! The last two blocks configure OSSEC to send an e-mail on our network. If we need a specific SMTP server, we can tweak it here. Once we have our e-mail configured, we establish the thresholds for alerting at events whose level is 7 or higher. We will log any events whose level is 1 or higher.

主站蜘蛛池模板: 玉门市| 金寨县| 永仁县| 石屏县| 明溪县| 天台县| 区。| 资阳市| 长垣县| 新沂市| 金昌市| 商城县| 隆昌县| 夹江县| 庄浪县| 洪洞县| 安达市| 鄂温| 方正县| 郯城县| 肇东市| 阿拉善右旗| 万盛区| 仁怀市| 甘泉县| 肥城市| 云梦县| 太仓市| 黔南| 怀柔区| 保亭| 揭阳市| 治多县| 富顺县| 额尔古纳市| 昔阳县| 湟源县| 安阳县| 买车| 花莲县| 礼泉县|