Linux processes monitoring through ossec

158 views
Skip to first unread message

yugandha...@gmail.com

unread,
Jul 21, 2017, 8:06:08 AM7/21/17
to ossec-list
Hi all,

I am new to ossec. I would like to monitor process through ossec. My plan is need to get the notification if some one start any new process or stop/kill any process.
Can some one help me

----
thanks,

dan (ddp)

unread,
Jul 21, 2017, 5:24:42 PM7/21/17
to ossec...@googlegroups.com
If there is a way to log all processes that are started, you could
configure OSSEC to read that log. Then create alerts or whatnot for
the entries.
Or, you could do a full_command with some `ps` wizardry.

> ----
> thanks,
>
> --
>
> ---
> You received this message because you are subscribed to the Google Groups
> "ossec-list" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to ossec-list+...@googlegroups.com.
> For more options, visit https://groups.google.com/d/optout.

Shyam Hirurkar

unread,
Jul 21, 2017, 9:03:25 PM7/21/17
to ossec...@googlegroups.com
Check Nagios for process monitoring

On 22-Jul-2017 02:54, "dan (ddp)" <ddp...@gmail.com> wrote:
On Fri, Jul 21, 2017 at 5:27 AM,  <yugandha...@gmail.com> wrote:
> Hi all,
>
> I am new to ossec. I would like to monitor process through ossec. My plan is
> need to get the notification if some one start any new process or stop/kill
> any process.
> Can some one help me
>

If there is a way to log all processes that are started, you could
configure OSSEC to read that log. Then create alerts or whatnot for
the entries.
Or, you could do a full_command with some `ps` wizardry.

> ----
> thanks,
>
> --
>
> ---
> You received this message because you are subscribed to the Google Groups
> "ossec-list" group.
> To unsubscribe from this group and stop receiving emails from it, send an

> For more options, visit https://groups.google.com/d/optout.

--

---
You received this message because you are subscribed to the Google Groups "ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ossec-list+unsubscribe@googlegroups.com.

Jesus Linares

unread,
Jul 24, 2017, 7:03:32 AM7/24/17
to ossec-list


On Saturday, July 22, 2017 at 3:03:25 AM UTC+2, CEH wrote:
Check Nagios for process monitoring
On 22-Jul-2017 02:54, "dan (ddp)" <ddp...@gmail.com> wrote:
On Fri, Jul 21, 2017 at 5:27 AM,  <yugandha...@gmail.com> wrote:
> Hi all,
>
> I am new to ossec. I would like to monitor process through ossec. My plan is
> need to get the notification if some one start any new process or stop/kill
> any process.
> Can some one help me
>

If there is a way to log all processes that are started, you could
configure OSSEC to read that log. Then create alerts or whatnot for
the entries.
Or, you could do a full_command with some `ps` wizardry.

> ----
> thanks,
>
> --
>
> ---
> You received this message because you are subscribed to the Google Groups
> "ossec-list" group.
> To unsubscribe from this group and stop receiving emails from it, send an

> For more options, visit https://groups.google.com/d/optout.

--

---
You received this message because you are subscribed to the Google Groups "ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ossec-list+...@googlegroups.com.

Kevin Wilcox

unread,
Jul 24, 2017, 7:50:10 AM7/24/17
to ossec...@googlegroups.com
On Fri, 21 Jul 2017 at 08:06, <yugandha...@gmail.com> wrote:

I am new to ossec. I would like to monitor process through ossec. My plan is need to get the notification if some one start any new process or stop/kill any process.
Can some one help me

auditd logging execve. You can also have it log file access and metadata updates.

kmw

Jesus Linares

unread,
Jul 25, 2017, 7:29:10 AM7/25/17
to ossec-list
Hi,


Regards.
Reply all
Reply to author
Forward
0 new messages