Share your knowledge at the LQ Wiki.
Go Back > Blogs > metalaarif
User Name


Rate this Entry

Receiving Email Notification from Samhain, Aide, OSSEC

Posted 01-02-2012 at 07:19 AM by metalaarif

###------This How I solved and Hope it helps everyone else who want Email Notification from Samhain, OSSEC and AIDE--------###

###------This one is for Samhain others i'll post it again soon------###
###------I'm doing this on Ubunutu------------------####

First of all,
Install postfix with "No Configuration"
Then # dpkg-reconfigure postfix
General type of mail configuration: Internet Site
System mail name: localhost
Root and postmaster mail recipient: anyname (e.g.John)
Other destinations for mail: (your hostname), localhost.localdomain, localhost
Force synchronous updates on mail queue?: No
Local networks:
Yes doesn't appear to be requested in current config
Mailbox size limit (bytes): 0
Local address extension character: +
Internet protocols to use: all
you can find this in here

Now once you have configured Postfix, We need to reconfigure it so that we can receive our Email Notification in our Gmail or Yahoomail or Hotmail etc.
This is one of the best link that guided me so that I could redirect my local mail to gmail

after you finish that process don't forget to try this but before that you need to install
sudo apt-get install mailutils && sudo apt-get install heirloom-mailx
Then use the following to see if you receive mail in gmail or yahoomail etc.
echo 'Testing Testing | mail -s 'This is Test mail'
If this is working then that means now you need to configure AIDE, Samhain and Ossec

For now I'll talk about Samhain
Install Samhain
vim /etc/samhainrc
First just configure what you want your samhain to scan and comments few files and directories which you don't have
then initialise the database
samhain -t init
Now check for any warning message in foreground or else it will run as daemon
samhain -t check -p warn --foreground
it will give few warning and alerts, now your ready to configure email part.
The reason we get Email notification that is because we have already created a database baseline
and now we are going to configure /etc/samhainrc, this is going change ctime, mtime, checksum etc
and this is very serious because main conf file is itself being changed. But we want to see Notification that is why we will do it now,
Remeber that your IP must be and now Make these changes
SetMailRelay =
Now again run,
samhain -t check -p warn --foreground
I'm 100% sure your going to get Email Notification Right away.
Good Luck I'll be posting for Aide and Ossec too
Posted in Uncategorized
Views 3414 Comments 0
« Prev     Main     Next »
Total Comments 0




All times are GMT -5. The time now is 06:01 PM.

Main Menu
Write for LQ is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration