X-Git-Url: http://ftp.carnet.hr/carnet-debian/scm?p=ossec-hids.git;a=blobdiff_plain;f=debian%2Fossec-hids%2Fusr%2Fshare%2Fdoc%2Fossec-hids%2Fcontrib%2Fossec_report.txt;fp=debian%2Fossec-hids%2Fusr%2Fshare%2Fdoc%2Fossec-hids%2Fcontrib%2Fossec_report.txt;h=6cfa383c2801990b773d6cfa1ed1c879c107ee82;hp=0000000000000000000000000000000000000000;hb=3f728675941dc69d4e544d3a880a56240a6e394a;hpb=927951d1c1ad45ba9e7325f07d996154a91c911b diff --git a/debian/ossec-hids/usr/share/doc/ossec-hids/contrib/ossec_report.txt b/debian/ossec-hids/usr/share/doc/ossec-hids/contrib/ossec_report.txt new file mode 100644 index 0000000..6cfa383 --- /dev/null +++ b/debian/ossec-hids/usr/share/doc/ossec-hids/contrib/ossec_report.txt @@ -0,0 +1,26 @@ +OSSEC report tool 0.1 +Licensed under GPL +Contributor Meir Michanie +ossec_report_contrib.pl [-h|--help] # This text you read now +ossec_report_contrib.pl [-r|--report] # prints a report for each element +ossec_report_contrib.pl [-s|--summary] # prints a summary report +ossec_report_contrib.pl [-t|--top] #prints the top list + +How To: +======= + +ossec_report_contrib.pl OSSEC report tool 0.1 +ossec_report_contrib.pl is a GNU style program. +It reads from STDIN and write to stdout. This gives you the advantage to use it in pipes. +i.e. +cat ossec-alerts-05.log | ossec_report_contrib.pl -r | mail root -s 'OSSEC detailed report' +cat ossec-alerts-05.log | ossec_report_contrib.pl -s | mail root -s 'OSSEC summary report' +cat | ossec_report_contrib.pl -t | head -n 15 (for top 15) +cat | ossec_report_contrib.pl -s (for summary) + +Crontab entry: +58 23 * * * (cat ossec-alerts-05.log | ossec_report_contrib.pl -s) + + +The could be any one of the variables used in ossec log: +mail,alerthost,datasource,rule,level,description,srcip,user.