ãã®è³æã¯ãOSSIMã·ã¹ãã ã«èå³ã®ããåå¿è
ã®ç®¡çè
ã«åœ¹ç«ã¡ãŸãã
ã·ã¹ãã ã®ã€ã³ã¹ããŒã«ã¯ãã§ã«ããã§è©³çŽ°ã«èª¬æãããŠããã®ã§ããã®æç¹ã§åæ¢ããŸããã
ãã®èšäºã§ã¯ããªã¢ãŒããã·ã³ã§å®è¡ãããŠããã¢ããªã±ãŒã·ã§ã³ããsyslogãããã³ã«ã䜿çšããŠãOSSIMã·ã¹ãã ãåä¿¡ããã€ãã³ããã°ãåŠçããããã®ãã©ã°ã€ã³ãäœæããæé ã«ã€ããŠèª¬æããŸãã ããã§ã¯ããã®ã¢ããªã±ãŒã·ã§ã³ã¯OSSIMã§ãµããŒããããŠããªãããšã«æ³šæããŠãã ããã ãããã£ãŠããã®æé ã¯ãsyslogãããã³ã«ã䜿çšããŠã€ãã³ããã°ãéä¿¡ããã¢ããªã±ãŒã·ã§ã³ã®ãã©ã°ã€ã³ãéçºããã®ã«é©ããŠããŸãã
ãã³ããŒã®ææžãåºç€ãšããŠäœ¿çšãããŸããã
Alienvault ã³ã¬ã¯ã¿ãŒãã©ã°ã€ã³ã®æ§ç¯
Alienvault ããŒã¿ãœãŒã¹ãã©ã°ã€ã³ãäœæããæ¹æ³
1.ãœãŒã¹ããŒã¿
1.1ã¢ãŒããã¯ãã£
IPã¢ãã¬ã¹ã192.168.0.111ã§ååãalienvaultã®ãOSSIMãã€ã³ã¹ããŒã«ããããµãŒããŒïŒä»¥éãOSSIMãµãŒããŒãšåŒã³ãŸãïŒã
IPã¢ãã¬ã¹ã192.168.0.54ãååãcnc-2ã®CentOS 6.6ãå®è¡ããŠãããµãŒããŒïŒä»¥äžããµãŒããŒãšåŒã³ãŸãïŒã ãµãŒããŒã«ã¢ããªã±ãŒã·ã§ã³ãã€ã³ã¹ããŒã«ãïŒbw_listsãšåŒã³ãŸãããïŒãsyslogãããã³ã«ãä»ããŠãªã¢ã«ã¿ã€ã ã§ã€ãã³ããã°ãOSSIMãµãŒããŒã«éä¿¡ããŸãã
ã¢ããªã±ãŒã·ã§ã³ã¯ããŠãŒã¶ãŒãå
¥åããã³ãã³ãã®ãã£ã«ã¿ãªã³ã°ãå®è¡ããæšæºã·ã§ã«ã®äžçš®ã®ä¿®æ£ã§ãã

å³1-ãœãªã¥ãŒã·ã§ã³ã¢ãŒããã¯ãã£
1.2ã€ãã³ãã®æ§é ã®èª¬æ
ã€ãã³ã圢åŒïŒ
<syslog圢åŒã®æ¥ä»> <ãã¹ãå> bw_lists [<ã»ãã·ã§ã³çªå·>]ïŒãŠãŒã¶ãŒïŒ<ãŠãŒã¶ãŒå> ipïŒ<ãµãŒããŒIP> ip_tkoïŒ<ã¿ãŒã²ããã·ã¹ãã ã®IP> INïŒ<ãŠãŒã¶ãŒå®è¡ã³ãã³ã> OUTïŒResïŒ<ã¬ããŒãå®è¡ãŸãã¯å€±æ> <ã³ãã³ãããã¹ã> <ã¿ãŒã²ããã·ã¹ãã åºå>
syslogãä»ããŠéä¿¡ããããã¹ãŠã®ã€ãã³ãã«ã¯ãã¢ããªã±ãŒã·ã§ã³ãå«ãŸããŸãã
1ïŒãŠãŒã¶ãŒã»ãã·ã§ã³çªå·ïŒbw_listsã®çŽåŸã®è§æ¬åŒ§å
ïŒ
2ïŒã³ãã³ããå®è¡ãããŠãŒã¶ãŒã®åå
3ïŒãã®ã³ãã³ããæ©èœãããµãŒããŒãšã¿ãŒã²ããã·ã¹ãã ã®IPã¢ãã¬ã¹
4ïŒãŠãŒã¶ãŒãå®è¡ããã³ãã³ãïŒããšãã°ãã端æ«ã®æ§æãïŒ
5ïŒãŠãŒã¶ãŒãçºè¡ããã³ãã³ãã®å®è¡ãŸãã¯æåŠã«é¢ããã¬ããŒãïŒACCEPTãŸãã¯DENYïŒ
6ïŒã³ã³ãœãŒã«ã§åä¿¡ããåºåïŒããšãã°ããæ§æã³ãã³ãã1è¡ã«1ã€ãã€å
¥åããŠãã ãããCNTL/ Zã§çµäºãïŒ
ã¢ããªã±ãŒã·ã§ã³ããåä¿¡ããã€ãã³ãã®äŸïŒ
Nov 20 14:15:33 cnc-2 bw_lists[19025]: user:oper1 ip:192.168.0.54 ip_tko:192.168.1.104 IN: configure terminal OUT: Res: ACCEPT configure terminal Enter configuration commands, one per line. End with CNTL/Z. Nov 20 14:15:39 cnc-2 bw_lists[19025]: user:oper1 ip:192.168.0.54 ip_tko:192.168.1.104 IN: interface Gi0/1 OUT: Res: ACCEPT interface Gi0/1 ^ % Invalid input detected at '^' marker. Nov 20 14:16:29 cnc-2 bw_lists[19025]: user:oper1 ip:192.168.0.54 ip_tko:192.168.1.104 IN: exit OUT: Res: ACCEPT exit
2.ã¿ã¹ã¯
1ïŒãµãŒããŒããsyslogãããã³ã«ã䜿çšããŠã€ãã³ããã°ãåä¿¡ãããã¡ã€ã«ã«æžã蟌ãããã«OSSIMãµãŒããŒã§èšå®ããŸãã
2ïŒOSSIMã·ã¹ãã ã§åä¿¡ããã€ãã³ããã°ã®è§£æãèšå®ããŸãã ããããã次ã®æ
å ±ãæœåºããå¿
èŠããããŸãã
- ãŠãŒã¶ãŒã»ãã·ã§ã³çªå·ïŒãbw_listsããšããèªã®çŽåŸã®è§æ¬åŒ§å ïŒ;
- ã³ãã³ããå®è¡ãããŠãŒã¶ãŒã®ååïŒãuserïŒãã®åŸïŒã
- ãµãŒããŒã®IPã¢ãã¬ã¹ïŒãipïŒãã®åŸïŒããã³ãã®ã³ãã³ããæ©èœããã¿ãŒã²ããã·ã¹ãã ïŒãip_tkoïŒãã®åŸïŒã
- ãŠãŒã¶ãŒãå®è¡ããã³ãã³ãïŒãINïŒãã®åŸãã端æ«ã®èšå®ããªã©ïŒã
- ãŠãŒã¶ãŒãæå®ããã³ãã³ãïŒãResïŒãã®åŸïŒã®å®è¡ãŸãã¯æåŠã®ã¬ããŒãïŒACCEPTãŸãã¯DENYïŒã
3.決å®
3.1ãµãŒããŒããã€ãã³ããã°ãåä¿¡ããããã®OSSIMãµãŒããŒã®æ§æ
ãã®ã¿ã¹ã¯ã®äžç°ãšããŠãsyslogãããã³ã«ã䜿çšããŠãµãŒããŒããéä¿¡ãããã€ãã³ããã°ãåä¿¡ããããã«ãrsyslogãOSSIMãµãŒããŒã§æ§æãããŸãã
ãããè¡ãã«ã¯ããã¡ã€ã«/etc/rsyslog.confãç·šéããŠã次ã®è¡ãè¿œå ããŸãã
if $programname contains 'bw_lists' then -/var/log/SR/bw-list-log.log
rsyslogãåèµ·åããŠãå€æŽãæå¹ã«ããŸãã
/etc/init.d/rsyslog restart
ãããã£ãŠãOSSIMãµãŒããŒããµãŒããŒããåä¿¡ãããbw_listsããå«ãã€ãã³ãã¯ã/ var / log / SR / bw-list-log.logãã¡ã€ã«ã«æžã蟌ãŸããŸãã 次ã«ãOSSIMèªäœã«ãã£ãŠãã®ãã¡ã€ã«ããã®ã€ãã³ãã®åæãæ§æããŸãã
3.2 OSSIMã§ã®åä¿¡ã€ãã³ãã®è§£æããã³è¡šç€ºã®æ§æ
OSSIMã§ã€ãã³ã解æãæ§æããããã»ã¹ã¯ã2ã€ã®æ®µéã«åããããŸãã
- ã€ãã³ããã°ã®æ§æãã¡ã€ã«ããŒãµãŒã®äœæã
- OSSIMããŒã¿ããŒã¹ã«ããŒãµãŒãšã€ãã³ãã®ã¿ã€ãã«é¢ããæ å ±ãè¿œå ããŸãã
- ãã©ã°ã€ã³ã®å å«ã
æåã®ãã¡ã€ã«ã¯ãã°èªäœã解æããOSSIMã䜿çšããã€ãã³ãèšè¿°ã¹ããŒã ã®ãã£ãŒã«ãå
šäœã«åä¿¡ããæ
å ±ãé
ä¿¡ããŸãã2çªç®ã®ãã¡ã€ã«ã¯ãOSSIMã€ã³ã¿ãŒãã§ã€ã¹ã§ã€ãã³ãã®ã¿ã€ããšã¯ã©ã¹ã衚瀺ããã€ãã³ãã«åªå
é äœãä»ããŸãã
OSSIMã¯ãæ¥ä»ããœãŒã¹IPãå®å
IPããŠãŒã¶ãŒåããŠãŒã¶ãŒããŒã¿1ã9ãªã©ã®ã€ãã³ããèšè¿°ããããã«ãæ°åã®ãã£ãŒã«ãã§æ§æãããã¹ããŒã ã䜿çšããŸãã ã¹ããŒã ã®è©³çŽ°ã¯ãªãã«èšèŒãããŠããŸãã OSSIMããã¥ã¡ã³ãã
3.2.1ã€ãã³ããã°ããŒãµãŒæ§æãã¡ã€ã«ã®äœæ
ããŒãµãŒãã¡ã€ã«ã¯OSSIMãµãŒããŒã®/ etc / ossim / agent / plugins /ãã£ã¬ã¯ããªã«ãããŸã
bwlistlog.cfgãšããååã§æ°ãããã¡ã€ã«ãäœæããŸãïŒååã¯ä»»æã«éžæã§ããŸãããäœã«ã圱é¿ãäžãããä»ã®ã©ãã«ã衚瀺ãããŸããããã ããååã¯å¿
ã<ã¹ããŒã¹ãªãã®è±æ°åã®çµã¿åãã> .cfgã®åœ¢åŒã«å¯Ÿå¿ããå¿
èŠããããŸãïŒã
åãã¡ã€ã«ã§ã¯ãããã€ãã®ã»ã¯ã·ã§ã³ã匷調衚瀺ããå¿
èŠããããŸãïŒã»ã¯ã·ã§ã³åã¯è§æ¬åŒ§ã§å²ãŸããŠããŸãïŒã
[ããã©ã«ã]
ãã®ã»ã¯ã·ã§ã³ã«ã¯ãã©ã°ã€ã³çªå·ããããŸãã ãã³ããŒã®æšå¥šã«ããããã©ã°ã€ã³çªå·ã¯9000ã10000ã®ç¯å²ããéžæããå¿
èŠããããŸãããã®çªå·ã¯ããã®OSSIMã€ã³ã¹ããŒã«ã«å¯ŸããŠäžæã§ããå¿
èŠããããŸãã
ãã©ã°ã€ã³ã«éžæããçªå·ã次ã®ããã«ããžãŒãã©ããã確èªããŸãã
grep "plugin_id = <ãã©ã°ã€ã³çªå·>" / etc / ossim / agent / plugins / *
äŸãã°
grep "plugin_id=9002" /etc/ossim/agent/plugins/*
[æ§æ]
ãã®ã»ã¯ã·ã§ã³ã¯ä»¥äžã瀺ããŸãã
- ãã©ã°ã€ã³ã®çš®é¡ã
- å«ãŸãããã©ããã
- ã¡ãã»ãŒãžãœãŒã¹ã®ã¿ã€ãã
- ã¡ãã»ãŒãžãä¿åããããã¡ã€ã«ã
- ã€ãã³ããçæããããã»ã¹ã®èšå®ïŒããã¯ã¢ãã¿ãŒã®ãããªãã©ã°ã€ã³ã«å¿ èŠã§ãïŒã
[翻蚳]
ãã®ã»ã¯ã·ã§ã³ã§ã¯ãã€ãã³ãã®ç¹å®ã®ãã£ãŒã«ãã®å€ã®ã翻蚳ããæ°å€ã«èšå®ã§ããŸãã ããã«ããããã®çªå·ã䜿çšããŠãããããããããã«ãã°ã©ãã£ã«ã«ã€ã³ã¿ãŒãã§ã€ã¹ã§ã€ãã³ãã¯ã©ã¹ãæå®ã§ããŸãã ã»ã¯ã·ã§ã³3.2.2ã®è©³çŽ°
äŸã®[bwlistlog]ãšåŒã°ããæåŸã®ã»ã¯ã·ã§ã³ã¯ãã¡ãã»ãŒãžã解æããæåã®ã«ãŒã«ã§ãã ã»ã¯ã·ã§ã³ã®åå-ã«ãŒã«ã¯ä»»æã®åœ¢åŒã«ããããšãã§ããŸãã 次ã®ããã«èšå®ããããšããå§ãããŸãïŒ[<number>-<source name>]ãããšãã°[1-applog]ã[2-applog]ãªã©ã
å®éã«ã¯ã1ã€ã®ãã©ã°ã€ã³å
ã§ãè€æ°ã®ã«ãŒã«ãèšå®ã§ããŸãã ã¡ãã»ãŒãžè§£æã¹ããŒã ã ããã¯ãç°ãªãæ§é ãæã€ã€ãã³ããåŠçããããã«è¡ãããŸãïŒ1ã€ã®è§£æã«ãŒã«ã䜿çšããŠãœãŒã¹ããã®ãã¹ãŠã®ã€ãã³ãã解æã§ããªãå ŽåïŒã
è€æ°ã®ã«ãŒã«ãããå ŽåãOSSIMã¯ã¡ãã»ãŒãžãããããã®ã«ãŒã«ãšé çªã«æ¯èŒãããã¥ãŒã¯ã¢ã«ãã¡ãããé ã«äžŠã¹ãããŸãã äŸ-[a-rule]ã[b-rule]ã[c-rule]ãšããååã®3ã€ã®ã«ãŒã«ããããŸãã æåã«aã«ãŒã«ã®é å®ããã§ãã¯ãã次ã«bã«ãŒã«ãªã©ããã§ãã¯ããŸãã ãããã£ãŠããã¥ãŒå
ã§æåŸã«æ©èœããããã«ãããäžè¬çãªã«ãŒã«ã«ååãä»ããããšããå§ãããŸãã
ã³ã¡ã³ãä»ãã®bwlistlog.cfgãã¡ã€ã«ã®å
容ïŒ
[DEFAULT] # ( OSSIM - plugin.) plugin_id=9002 [config] # plugin'. - detector monitor. syslog detector type=detector # enable=yes # . log - . database ( ), sdee ( cisco), snortlog ( snort), wmi ( Windows wmi) source=log # , . location=/var/log/SR/bw-list-log.log # OSSIM . create_file=true # - OSSIM. , OSSIM, , - process= start=no stop=no startup= shutdown= # "" [translation] ACCEPT=1 DENY=2 # (, , ) . [bwlistlog] # . event_type=event # , regexp="^((?P<date>\S+\s+\d+\s+\d+:\d+:\d+)\s+(?P<sensor>\S+)\s+bw_lists\[(?P<session>\d+)\]\:\s+user\:(?P<user>\S+)\s+ip\:(?P<sr_node>\S+)\s+ip_tko\:(?P<tko_node>\S+)\s+IN\:(?P<message>.*)\s+OUT\:\s+Res\:\s+(?P<result>\S+).*)" # , , OSSIM. 3.2.3 device={$sr_node} date={normalize_date($date)} plugin_sid={translate($result)} src_ip={$tko_node} username={$user} userdata1={$message} userdata2={$session}
ãã®æ£èŠè¡šçŸã§ã¯ãæœåºããæ å ±ã匷調衚瀺ïŒãã£ãã䜿çšïŒããä»»æã®ã¿ã°ãããã«å²ãåœãŠãŸãïŒçå笊ãæåPãè§ãã£ãïŒP <>ã䜿çšïŒããããåç §ããŠäœ¿çšã§ããŸãã äŸïŒ
(?P<date>\S+\s+\d+\s+\d+:\d+:\d+)
åŒ\ S + \ s + \ d + \ s + \ d +ïŒ\ d +ïŒ\ d +ã«è©²åœããè¡ã®å é ã®æ å ±ã¯ããdateãã¿ã°ã䜿çšããŠã¢ãã¬ã¹æå®ãããŸãã ããã«ãOSSIMã¹ããŒã ã®ãdateããã£ãŒã«ãã«ããdateããã£ãŒã«ãã®å€ãæåã«æ£èŠåããåŸã«é 眮ããããšãå ±åããŸãïŒOSSIMã¯ãããŸããŸãªåœ¢åŒã®æ¥ä»ãç¬èªã®åœ¢åŒã«å€æã§ããŸãïŒã
date={normalize_date($date)}
æ£èŠè¡šçŸããã¹ãããã«ã¯ãããšãã°ãã®ããŒã«ã䜿çšã§ããŸã ã ãã®ããŒã«ã¯ã¿ã°ã®æäœæ¹æ³ãèªèããŠããªãããšã«æ³šæããŠãã ããã ãããã£ãŠãæ£èŠè¡šçŸããã¹ãããåŸãããããè¿œå ããå¿
èŠããããŸãã
ãŸãããã£ãŒã«ããplugin_sidãã説æããå¿
èŠããããŸãã åããplugin_idããæã€åããœãŒã¹ããã®ã€ãã³ãã¯ãç°ãªãã¯ã©ã¹ã«å±ããããšãã§ããŸããããšãã°ããã®äŸã§ã¯ãACCEPTããšãDENYãã§ãã ãplugin_sidãã¯ã¯ã©ã¹èå¥åãšæ¬¡ã®è¡ãæãã ãã§ãïŒ
plugin_sid={translate($result)}
[çµæ]ã¿ã°ã§åä¿¡ããæ
å ±ã翻蚳ããããã«[translate]ã»ã¯ã·ã§ã³ã«ç§»åããããã«ããŒãµãŒã«æ瀺ããŸãã ãACCEPTãã¯ãŠãããããDENYã-ãã¥ãŒã¹ã«å€æãããŸãã ã€ãã³ãã¯ã©ã¹ãå²ãåœãŠãæ¹æ³ãšçç±ã«ã€ããŠã¯ã次ã®ã»ã¯ã·ã§ã³ã§èª¬æããŸãã
ã¯ãã次ã®ããã«æå®ããããšã«ãããplugin_sidãå解æã«ãŒã«ã«æåã§å²ãåœãŠãããšãã§ããŸãã
plugin_sid=1
3.2.2 OSSIMããŒã¿ããŒã¹ãžã®ããŒãµãŒæ å ±ãšã€ãã³ãã¿ã€ãã®è¿œå
ããŒãµãŒæ§æãã¡ã€ã«ãæžã蟌ãã åŸããã®æ
å ±ãOSSIMããŒã¿ããŒã¹ã«è¿œå ããå¿
èŠããããŸãã
ããã¯ãmysqlã¹ã¯ãªãããèšè¿°ããŠå®è¡ããããšã«ããè¡ãããŸãã ãµã³ãã«ã¹ã¯ãªããã¯ãOSSIMãµãŒããŒã®æ¬¡ã®ãã©ã«ããŒã«ãããŸãã
/ usr / share / doc / ossim-mysql / contrib /ãã©ã°ã€ã³/
ã¹ã¯ãªããã®ååã¯ä»»æã«éžæã§ããŸãã
ããããããããããã«ãäŸããããã«ã¹ã¯ãªããã瀺ããŸãã
DELETE FROM plugin WHERE id = "9002"; DELETE FROM plugin_sid where plugin_id = "9002"; INSERT IGNORE INTO plugin (id, type, name, description) VALUES (9002, 1, 'bw-lists', 'Bash filtering'); INSERT IGNORE INTO plugin_sid (plugin_id, sid, category_id, class_id, name) VALUES (9002, 1, NULL, NULL, 'Command Accepted'); INSERT IGNORE INTO plugin_sid (plugin_id, sid, category_id, class_id, name) VALUES (9002, 2, NULL, NULL, 'Command Denied');
æåã®3è¡ã¯ãplugin_idçªå·9002ãžã®å€ãåç
§ããã¹ãŠããŒã¿ããŒã¹ããã¯ãªã¢ããåäœæããŸãã
次ã®2ã€ã¯ãã€ãã³ãã¯ã©ã¹ã«ã€ããŠèª¬æããŠããŸãã
åã®ã»ã¯ã·ã§ã³ã§æãåºããããã«ããplugin_sidãã¯ãã¿ã°ãresultãïŒãããããACCEPTããšãDENYãïŒã®äžã®ããŒãµãŒã䜿çšããŠã€ãã³ãããåä¿¡ããæ
å ±ãçžé¢ãããããã[translate]ã»ã¯ã·ã§ã³ïŒæ§æãã¡ã€ã«ããŒãµãŒïŒã ãããã£ãŠã2ã€ã®ã¯ã©ã¹ã®ã€ãã³ã1-"ACCEPT"ã2-"DENY"ããããŸãã
ãããã®ã¯ã©ã¹ã®ã€ãã³ãã¯ãOSSIMããŒã¿ããŒã¹è¡ã«ãã£ãŠå ±åãããŸãã
INSERT IGNORE INTO plugin_sid (plugin_id, sid, category_id, class_id, name) VALUES (9002, 1, NULL, NULL, 'Command Accepted'); INSERT IGNORE INTO plugin_sid (plugin_id, sid, category_id, class_id, name) VALUES (9002, 2, NULL, NULL, 'Command Denied');
mysqlæ§æã«ç²ŸéããŠãã人ã¯ç°¡åã«ç解ã§ããŸãã æ®ãã«ã€ããŠã¯ãOSSIMã€ã³ã¿ãŒãã§ãŒã¹ã§ãACCEPTããšåé¡ãããã€ãã³ãã¯ããããããCommand AcceptedãããDENYãããCommand Deniedããšããååã§è¡šç€ºãããããšã説æããŸãã ããã§ã¯ããã®ã¿ã€ãã®ãœãŒã¹ïŒcategory_idãclass_idïŒã®ã€ãã³ãåé¡ãªãã·ã§ã³ãèšå®ããããšãã§ããŸãã
ã¹ã¯ãªãããäœæãããã次ã®ã³ãã³ãã䜿çšããŠOSSIMããŒã¿ããŒã¹ã«ããŒãããå¿
èŠããããŸãã
# ossim-db < /usr/share/doc/ossim-mysql/contrib/plugins/bw-lists.sql
3.2.3ãã©ã°ã€ã³ãæå¹ã«ãã
次ã®ããã«ããŠãäœæãããã©ã°ã€ã³ãæå¹ã«ã§ããŸãã
1ïŒSSHãä»ããŠOSSIMãµãŒããŒã«æ¥ç¶ããã¡ãã¥ãŒã«ç§»åããŸãïŒ[ã»ã³ãµãŒã®èšå®]-[ããŒã¿ãœãŒã¹ãã©ã°ã€ã³ã®èšå®];
2ïŒãªã¹ãã§ãã©ã°ã€ã³ãbw-listsããèŠã€ãããã®æšªã«ã*ããå ¥åããŠããOKããã¯ãªãã¯ããŸãã
3ïŒ[æ»ã]ãã¿ã³ã䜿çšããŠã«ãŒãã¡ãã¥ãŒã«æ»ããŸãã
4ïŒ[ãã¹ãŠã®å€æŽãé©çš]ãªãã·ã§ã³ãéžæããŸãã
æ°ãããã©ã°ã€ã³ã¯ãã€ãã³ããã°ãåŠçããæºåãã§ããŠããŸãã
ãã ããã€ãã³ããå°çããããOSSIMã€ã³ã¿ãŒãã§ãŒã¹ã§ã¯ããã©ã°ã€ã³ã¿ã€ãã§ãœãŒãããå Žåããããã¯è¡šç€ºãããŸããã
4.ãã©ãã«ã·ã¥ãŒãã£ã³ã°
1ïŒããŒãµãŒæ§æãã¡ã€ã«ã§æå®ããããã°ãã¡ã€ã«ãååšãããã®äžã®ã¬ã³ãŒããæŽæ°ãããŠããããšã確èªããŸã-ã€ãŸã éèªãå°çããŸãã
2ïŒã€ãã³ã圢åŒãäœæããæ£èŠè¡šçŸãšäžèŽããããšã確èªããŸãã
3ïŒãã¡ã€ã«/var/log/alienvault/agent/agent.logã§ãã©ã°ã€ã³ã«é¢é£ãããšã©ãŒã確èªããŸãã
grep ERR /var/log/alienvault/agent/agent.log|grep 9002 grep Discard /var/log/alienvault/agent/agent.log|grep 9002 grep Warn /var/log/alienvault/agent/agent.log|grep 9002