LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
Search this Thread
Old 05-27-2008, 11:12 AM   #1
mccartjd
Member
 
Registered: Apr 2008
Posts: 107

Rep: Reputation: 15
Smile Setup SNARE Objective on RHEL WS 4 Release 4 Agent


Can anyone tell me what values (drop downs and fill in) to place in the SNARE Agnet Objectives fields if I wish to monitor failed attempts to write to the /etc directory?

I was told from the objective screen to select from left to right:

Criticality 3 Orange

Events Read/Write a File/Directory

Return Failure

User Any

Match name
/etc/

Next select "Change Configuration", "Apply Configuration"

After perform the following settings general users who fail to write a test file to the /etc/ directory still do not reflect their failed attempts in the in the SNARE; Display Recent events Windows.

Any thougths,
Thanks
John
 
Old 06-06-2008, 07:45 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 27,277
Blog Entries: 54

Rep: Reputation: 2852Reputation: 2852Reputation: 2852Reputation: 2852Reputation: 2852Reputation: 2852Reputation: 2852Reputation: 2852Reputation: 2852Reputation: 2852Reputation: 2852
Maybe you want http://www.intersectalliance.com/res..._for_Linux.pdf, Appendix C - Configuration File Description?
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
RHEL 4 - Auditing, LAuS, SNARE. mccartjd Linux - Security 12 01-26-2009 04:24 PM
setup agent ronmann Fedora 2 01-06-2008 04:18 AM
squid problem on RHEL Release 5 Dogar Linux - Enterprise 7 09-03-2007 06:24 PM
Setup Agent truncated during FC6 post-install MIchael_Friday Fedora - Installation 1 12-24-2006 11:12 AM
DHCP relay agent on RHEL 4.0 santhavilas Red Hat 0 01-16-2006 01:00 AM


All times are GMT -5. The time now is 08:48 PM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration