Configuring logsurfer


 
Thread Tools Search this Thread
Operating Systems Solaris Configuring logsurfer
# 1  
Old 04-25-2012
Configuring logsurfer

I had trouble initially compiling logsurfer, but wrote the developer and he said there was a change made that affected Solaris, so I got that fixed. I then looked for examples and found a config file I could use for ssh. I sent things up and was email on a failed ssh attempt. The trouble is, I don't understand the makeup of the config file. Does anyone know of an explained example or something that explains the config file in greater detail? Here is what I have minus the actual IP addresses:

pr 24 15:24:05 appoc4 sshd[25301]: [ID 800047 auth.info] Did not receive identification string from 199.123.122.70 Apr 24 15:24:05 appoc4 rsh[25303]: [ID 521673 daemon.notice] connection from noscdb.ism.army.mil (X.X.X.X) - bad port Apr 24 15:24:05 appoc4 rlogind[25304]: [ID 846982 daemon.notice] connection from [removed machine name](X.X.X.X) - bad port

From this I was able to turn off the "r" commands, but I thought I was only looking for ssh:
###
### ssh daemons
### $Id: ssh.txt,v 1.1 2002/03/09 18:26:23 emf Exp $
###

###
### SSH
###
'.* sshd\[.* Generating new .* key.*' - - - 0 ignore
'.* sshd\[.* key generation complete.*' - - - 0 ignore
'.* sshd\[.* error: accept: Connection reset by peer' - - - 0 ignore
'.* sshd\[.* Warning:.* keysize mismatch: actual 1023 vs. announced 1024.' - - - 0 ignore
'^.{16,}(.*) sshd\[.* (Accepted|Postponed) (.*) for (.*) from (.*) port (.*).*' - - - 0 ignore
'^.{16,}(.*) sshd\[.* log: Connection from (.*) port (.*)' - - - 0 ignore
'^.{16,}(.*) sshd\[.* log: RSA authentication for (.*) accepted.*' - - - 0 ignore
'^.{16,}(.*) sshd\[.* Setting tty modes failed: Invalid argument.*' - - - 0 ignore
'^.{15,} (.*) sshd\[.* log: Could not reverse map address (.*)' - - - 0 ignore
'^.{15,} (.*) sshd\[.* log: (Closing connection to|Connection closed by) (.*)' - - - 0 ignore
'^.{15,} (.*) sshd\[.* Did not receive (ident|identification) string from (.*)' - - - 0
open "$4" - 5000 1800 90
report "/usr/local/bin/surfmailer -r sa-team -S \"security incident from $4\"" "$4"
'^.{15,} (.*) sshd\[.* Bad protocol version identification .* from (.*)' - - - 0
open "$3" - 5000 1800 90
report "/usr/local/bin/surfmailer -r sa-team -S \"security incident from $3\"" "$3"
'^.{15,} (.*) sshd\[.* scanned from (.*) with SSH-1.0-SSH_Version_Mapper' - - - 0
open "$3" - 5000 1800 90
report "/usr/local/bin/surfmailer -r sa-team -S \"security incident from $3\" (scanssh)" "$3"
'^.{15,} (.*) sshd\[.* Disconnecting: Corrupted check bytes on input.' - - - 0
open "$2" - 100 1800 90
report "/usr/local/bin/surfmailer -r sa-team -S \"Possible SSH Attack in progress against $2\"" "$2"
'^.{15,} (.*) sshd\[(.*)\]: Failed password for (.*) from (.*) port .*' - - - 0
open "$2 sshd:\\[$3\\]:" - 5000 10800 300
report "/usr/local/bin/surfmailer -r sa-team -S \"SSH LOGIN FAILED for $4@$2 from $5\"" "$2 sshd:\\[$3\\]:"
Login or Register to Ask a Question

Previous Thread | Next Thread

10 More Discussions You Might Find Interesting

1. Solaris

Configuring Auditing

Hello Solaris Team, We would like to implement some audit policy (using a log file) in Solaris 10 in order to record the following data in columns per all users: 1. Date 2. Time 3. User 4. Command executed 5. Terminal 6. IP Address Could you please help me in order to... (2 Replies)
Discussion started by: csierra
2 Replies

2. UNIX for Dummies Questions & Answers

Need help configuring SSH on HP-UX

Can someone show me the basics on configuring SSH on Unix so I can access my Unix account remotely from Windows 7. Basically, I want to fire some scripts remotely. I've already posted a thread on the Windows forum thinking my configuration was wrong on the Windows side. But the more I read the... (9 Replies)
Discussion started by: rm-r
9 Replies

3. Red Hat

configuring X on Enterprise v6.2

Hello; nerw to configuring X windows on redhat .. After a fresh install of Enterprise v6.2 w/ kde desktop pkg, noticed the follwing: 1. metacity wm is installed 2. gdm also seems to be running 3. trying to connect from Reflection fails Where can I find a how to guide ?? Thnx (1 Reply)
Discussion started by: delphys
1 Replies

4. Shell Programming and Scripting

Configuring ssmtp

Hi, I have trouble in configuring ssmtp for sending mail to gmail. I have configured the following way, plz suggest/correct me if i have done something wrong root=nagiostool@gmail.com mailhub=smtp.gmail.com:587 #RewriteDomain= # The full hostname Hostname=nagiosxi # Set this to... (1 Reply)
Discussion started by: nagios
1 Replies

5. Red Hat

configuring vsftpd

hi everybody, i am new to linux. iam using centos 6.2, and trying to configure ftp server in my local network, i have seen one fpt server how to videos tutriol but iam unable to follow i have some confussion in /etc/vsftpd/vsftpd.conf about userlist_enable and userlist_deny,... (6 Replies)
Discussion started by: paruhang
6 Replies

6. Solaris

Samba help Configuring.

I am trying to find some documentation to help me configure SAMBA on a Solaris 10 OS for File Sharing. I guess I need more help on the smb.conf file. I was able to test a small smb.conf file and testparm script works. So, I know I have installed it properly. Now looking for more guidance of the... (2 Replies)
Discussion started by: 4X4R8D
2 Replies

7. UNIX for Dummies Questions & Answers

Configuring Chrootdirectory

Hello, I am running OpenSSH_4.3p2, OpenSSL 0.9.8e-fips-rhel5 01 Jul 2008 I need to chroot each user into their own directory. How can I do so using the chrootdirectory option? Please provide an example. Thanks (0 Replies)
Discussion started by: mojoman
0 Replies

8. UNIX for Dummies Questions & Answers

help configuring Ajaxterm

Hello there, I installed Ajaxterm on my Ubuntu 9.04 machine, and it's running ok if I use :http://localhost:8022/ in my broswer. This is the problem , it can only be accessed localy. If I want to access it through internet from another computer, it fails. I've read the tutorials on how to... (1 Reply)
Discussion started by: wosis
1 Replies

9. UNIX for Advanced & Expert Users

Configuring a modem on a P5

Hello. I'm trying to configure a modem on an IBM p570 on the serial port. This is a partition machine so i want to be able to share it with partitionned servers. On my VIOserver, what needs to be done exactly? I can see a vsa0 device but that is not the serial port i need from what i... (1 Reply)
Discussion started by: Stephan
1 Replies

10. UNIX for Advanced & Expert Users

Configuring.....

Hi Folks, I would like to learn the basics of unix administration like configuring telnet, ftp, smtp,etc.. Could u suggest me a good site for learning it??? or the methodology that has to be followed for learning it??? TIA, Nisha :) (2 Replies)
Discussion started by: Nisha
2 Replies
Login or Register to Ask a Question