[osiris] responses to integrity check failure
Darren Spruell
phatbuckett at gmail.com
Wed Dec 20 12:17:20 EST 2006
Does Osiris provide for j(or is there a commonly suggested method of)
setting up configurable responses to detected integrity check
failures?
We have a number of systems that we wish to automatically respond to
immediately upon detection of a modification on the monitored
filesystem, such as shutting the host down, executing an external
script, etc.
>From the docs I understand that the only alerting mechanism is
currently email, so I could see doing something like parsing out the
email using procmail or running swatch against the mailbox or
something. Is there a more sophisticated response procedure people are
using, or is it possible to have osiris report integrity check events
via syslog?
DS
More information about the osiris
mailing list