<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="mn">
		<id>https://wiki.dusal.net/index.php?action=history&amp;feed=atom&amp;title=OSSEC_%D1%81%D0%B5%D1%80%D0%B2%D0%B5%D1%80%D0%B8%D0%B9%D0%BD_%D0%B0%D1%8E%D1%83%D0%BB%D0%B3%D2%AF%D0%B9_%D0%B1%D0%B0%D0%B9%D0%B4%D0%BB%D1%8B%D0%BD_%D1%85%D1%8F%D0%BD%D0%B0%D0%BB%D1%82%D1%8B%D0%BD_%D1%81%D0%B5%D1%80%D0%B2%D0%B8%D1%81</id>
		<title>OSSEC серверийн аюулгүй байдлын хяналтын сервис - Түүх</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.dusal.net/index.php?action=history&amp;feed=atom&amp;title=OSSEC_%D1%81%D0%B5%D1%80%D0%B2%D0%B5%D1%80%D0%B8%D0%B9%D0%BD_%D0%B0%D1%8E%D1%83%D0%BB%D0%B3%D2%AF%D0%B9_%D0%B1%D0%B0%D0%B9%D0%B4%D0%BB%D1%8B%D0%BD_%D1%85%D1%8F%D0%BD%D0%B0%D0%BB%D1%82%D1%8B%D0%BD_%D1%81%D0%B5%D1%80%D0%B2%D0%B8%D1%81"/>
		<link rel="alternate" type="text/html" href="https://wiki.dusal.net/index.php?title=OSSEC_%D1%81%D0%B5%D1%80%D0%B2%D0%B5%D1%80%D0%B8%D0%B9%D0%BD_%D0%B0%D1%8E%D1%83%D0%BB%D0%B3%D2%AF%D0%B9_%D0%B1%D0%B0%D0%B9%D0%B4%D0%BB%D1%8B%D0%BD_%D1%85%D1%8F%D0%BD%D0%B0%D0%BB%D1%82%D1%8B%D0%BD_%D1%81%D0%B5%D1%80%D0%B2%D0%B8%D1%81&amp;action=history"/>
		<updated>2026-05-04T12:29:21Z</updated>
		<subtitle>Вики дэх энэ хуудасны засварын түүх</subtitle>
		<generator>MediaWiki 1.30.0</generator>

	<entry>
		<id>https://wiki.dusal.net/index.php?title=OSSEC_%D1%81%D0%B5%D1%80%D0%B2%D0%B5%D1%80%D0%B8%D0%B9%D0%BD_%D0%B0%D1%8E%D1%83%D0%BB%D0%B3%D2%AF%D0%B9_%D0%B1%D0%B0%D0%B9%D0%B4%D0%BB%D1%8B%D0%BD_%D1%85%D1%8F%D0%BD%D0%B0%D0%BB%D1%82%D1%8B%D0%BD_%D1%81%D0%B5%D1%80%D0%B2%D0%B8%D1%81&amp;diff=326&amp;oldid=prev</id>
		<title>Almas: Хуудас үүсгэв: &quot;OSSEC is a free, open-source host-based intrusion detection system by Trend Micro. It performs log analysis, integrity checking, Windows registry monitoring, rootkit...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.dusal.net/index.php?title=OSSEC_%D1%81%D0%B5%D1%80%D0%B2%D0%B5%D1%80%D0%B8%D0%B9%D0%BD_%D0%B0%D1%8E%D1%83%D0%BB%D0%B3%D2%AF%D0%B9_%D0%B1%D0%B0%D0%B9%D0%B4%D0%BB%D1%8B%D0%BD_%D1%85%D1%8F%D0%BD%D0%B0%D0%BB%D1%82%D1%8B%D0%BD_%D1%81%D0%B5%D1%80%D0%B2%D0%B8%D1%81&amp;diff=326&amp;oldid=prev"/>
				<updated>2018-10-08T03:23:29Z</updated>
		
		<summary type="html">&lt;p&gt;Хуудас үүсгэв: &amp;quot;OSSEC is a free, open-source host-based intrusion detection system by Trend Micro. It performs log analysis, integrity checking, Windows registry monitoring, rootkit...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Шинэ хуудас&lt;/b&gt;&lt;/p&gt;&lt;div&gt;OSSEC is a free, open-source host-based intrusion detection system by Trend Micro. It performs log analysis, integrity checking, Windows registry monitoring, rootkit detection, time-based alerting, and active response.&lt;br /&gt;
&lt;br /&gt;
== Debian дээр суулгах ==&lt;br /&gt;
&lt;br /&gt;
OSSEC’s deb packages are available in the Wazuh repository.&lt;br /&gt;
&lt;br /&gt;
Install the apt-get repository key:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# apt-key adv --fetch-keys http://ossec.wazuh.com/repos/apt/conf/ossec-key.gpg.key&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Add the repository for Debian (available distributions are Sid, Jessie and Wheezy):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# echo 'deb http://ossec.wazuh.com/repos/apt/debian wheezy main' &amp;gt;&amp;gt; /etc/apt/sources.list&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Or add the repository for Ubuntu (available distributions are Precise, Trusty and Utopic):&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# echo 'deb http://ossec.wazuh.com/repos/apt/ubuntu precise main' &amp;gt;&amp;gt; /etc/apt/sources.list&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Update the repository:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# apt-get update&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Install OSSEC HIDS server/manager:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# apt-get install ossec-hids&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Or install OSSEC HIDS agent:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# apt-get install ossec-hids-agent&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Сервер менежерт агент нэмэх ==&lt;br /&gt;
&lt;br /&gt;
Run manage_agents:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# /var/ossec/bin/manage_agents&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The manage_agents menu:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
****************************************&lt;br /&gt;
* OSSEC HIDS v2.5-SNP-100809 Agent manager.     *&lt;br /&gt;
* The following options are available: *&lt;br /&gt;
****************************************&lt;br /&gt;
   (A)dd an agent (A).&lt;br /&gt;
   (E)xtract key for an agent (E).&lt;br /&gt;
   (L)ist already added agents (L).&lt;br /&gt;
   (R)emove an agent (R).&lt;br /&gt;
   (Q)uit.&lt;br /&gt;
Choose your action: A,E,L,R or Q:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Typing the appropriate letter and hitting enter will initiate that function.&lt;br /&gt;
&lt;br /&gt;
=== Adding an agent ===&lt;br /&gt;
&lt;br /&gt;
To add an agent type a in the start screen:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Choose your action: A,E,L,R or Q: a&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
You are then prompted to provide a name for the new agent. This can be the hostname or another string to identify the system. In this example the agent name will be agent1.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
- Adding a new agent (use '\q' to return to the main menu).&lt;br /&gt;
  Please provide the following:&lt;br /&gt;
   * A name for the new agent: agent1&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
After that you have to specify the IP address for the agent. This can either be a single IP address (e.g. 192.168.1.25), a range of IPs (e.g. 192.168.2.0/24), or any. Using a network range or any is preferable when the IP of the agent may change frequently (DHCP), or multiple systems will appear to come from the same IP address (NAT).&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
* The IP Address of the new agent: 192.168.2.0/24&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Warning'''&lt;br /&gt;
&lt;br /&gt;
''If you use a specific IP address it must be unique. Duplicate IP addresses will cause issues. Multiple systems can use the same IP range or any.''&lt;br /&gt;
&lt;br /&gt;
The last information you will be asked for is the ID you want to assign to the agent. manage_agents will suggest a value for the ID. This value should be the lowest positive number that is not already assigned to another agent. The ID 000 is assigned to the OSSEC server. To accept the suggestion, simply press ENTER. To choose another value, type it in and press ENTER.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
* An ID for the new agent[001]:&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As the final step in creating an agent, you have to confirm adding the agent:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Agent information:&lt;br /&gt;
   ID:002&lt;br /&gt;
   Name:agent1&lt;br /&gt;
   IP Address:192.168.2.0/24&lt;br /&gt;
&lt;br /&gt;
Confirm adding it?(y/n): y&lt;br /&gt;
Agent added.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
After that manage_agents appends the agent information to /var/ossec/etc/client.keys and goes back to the start screen.&lt;br /&gt;
&lt;br /&gt;
'''Warning'''&lt;br /&gt;
&lt;br /&gt;
''If this is the first agent added to this server, the server’s OSSEC processes should be restarted using /var/ossec/bin/ossec-control restart.''&lt;br /&gt;
&lt;br /&gt;
=== Extracting the key for an agent ===&lt;br /&gt;
&lt;br /&gt;
After adding an agent, a key is created. This key must be copied to the agent. To extract the key, use the e option in the manage_agents start screen. You will be given a list of all agents on the server. To extract the key for an agent, simply type in the agent ID. It is important to note that you have to enter all digits of the ID.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Choose your action: A,E,L,R or Q: e&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Available agents:&lt;br /&gt;
   ID: 001, Name: agent1, IP: 192.168.2.0/24&lt;br /&gt;
Provide the ID of the agent to extract the key (or '\q' to quit): 001&lt;br /&gt;
&lt;br /&gt;
Agent key information for '001' is:&lt;br /&gt;
MDAyIGFnZW50MSAxOTIuMTY4LjIuMC8yNCBlNmY3N2RiMTdmMTJjZGRmZjg5YzA4ZDk5m&lt;br /&gt;
&lt;br /&gt;
** Press ENTER to return to the main menu.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The key is encoded in the string (shortened for this example) MDAyIGFnZW50MSAxOTIuMTY4LjIuMC8yNCBlNmY3N2RiMTdmMTJjZGRmZjg5YzA4ZDk5Mm and includes information about the agent. This string can be added to the agent through the agent version of manage_agents.&lt;br /&gt;
&lt;br /&gt;
=== Removing an agent ===&lt;br /&gt;
&lt;br /&gt;
If you want to remove an OSSEC agent from the server, use the r option in the manage_agents start screen. You will be given a list of all agents already added to the server. To remove an agent, simply type in the ID of the agent, press enter, and finally confirm the deletion. It is important to note that you have to enter all digits of the ID.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Choose your action: A,E,L,R or Q: r&lt;br /&gt;
&lt;br /&gt;
Available agents:&lt;br /&gt;
   ID: 001, Name: agent1, IP: 192.168.2.0/24&lt;br /&gt;
Provide the ID of the agent to be removed (or '\q' to quit): 001&lt;br /&gt;
Confirm deleting it?(y/n): y&lt;br /&gt;
Agent '001' removed.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
manage_agents then invalidates the agent information in /var/ossec/etc/client.keys. Only the values for ID and the key are kept to avoid conflicts when adding agents. The deleted agent can no longer communicate with the OSSEC server.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== manage_agents on OSSEC agents ===&lt;br /&gt;
&lt;br /&gt;
The agent version provides an interface for importing authentication keys.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
****************************************&lt;br /&gt;
* OSSEC HIDS v2.5-SNP-100809 Agent manager.     *&lt;br /&gt;
* The following options are available: *&lt;br /&gt;
****************************************&lt;br /&gt;
   (I)mport key from the server (I).&lt;br /&gt;
   (Q)uit.&lt;br /&gt;
Choose your action: I or Q: i&lt;br /&gt;
&lt;br /&gt;
* Provide the Key generated by the server.&lt;br /&gt;
* The best approach is to cut and paste it.&lt;br /&gt;
*** OBS: Do not include spaces or new lines.&lt;br /&gt;
&lt;br /&gt;
Paste it here (or '\q' to quit): [key extracted via manage_agents on the server]&lt;br /&gt;
&lt;br /&gt;
Agent information:&lt;br /&gt;
   ID:001&lt;br /&gt;
   Name:agent1&lt;br /&gt;
   IP Address:192.168.2.0/24&lt;br /&gt;
&lt;br /&gt;
Confirm adding it?(y/n): y&lt;br /&gt;
Added.&lt;br /&gt;
** Press ENTER to return to the main menu.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For the changes to be in effect you have to restart the server and start the agent.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Ангилал:Сисадмин]]&lt;br /&gt;
[[Ангилал:Linux]][[Ангилал:Зааварчилгаа]][[Ангилал:Нээлттэй_эх]]&lt;/div&gt;</summary>
		<author><name>Almas</name></author>	</entry>

	</feed>