Tripwire: Notifikasi e-mail: Difference between revisions

From OnnoCenterWiki
Jump to navigationJump to search
Onnowpurbo (talk | contribs)
New page: Tripwire and Email Tripwire can email someone if a specific type of rule in the policy file is violated. To configure Tripwire to do this, you first have to know the email address of the ...
 
Onnowpurbo (talk | contribs)
No edit summary
Line 1: Line 1:
Tripwire and Email
Kita dapat melaporkan kejadian menggunakan tripwire dan ini harus ditulis pada file Tripwire


Tripwire can email someone if a specific type of rule in the policy file is violated. To configure Tripwire to do this, you first have to know the email address of the person to be contacted if a particular integrity violation occurs, plus the name of the rule you would like to monitor. Note that on large systems with multiple administrators, you can have different sets of people notified for certain violations and no one notified for minor violations.
/etc/tripwire/twpol.txt


Once you know who to notify and what to notify them about, add an emailto= line to the rule directive section of each rule. Do this by adding a comma after the severity= line and putting emailto= on the next line, followed by the email addresses to send the violation reports for that rule. Multiple emails will be sent if more than one email address is specified and they are separated by a semi-colon.
contoh e-mail admin bob@domain.com;sam@domain.com


For example, if you would like two administrators, Sam and Bob, notified if a networking program is modified, change the Networking Programs rule directive in the policy file to look like this:
(
  rulename = "Networking Programs",
  severity = $(SIG_HI),
  emailto = bob@domain.com;sam@domain.com
)


(
  rulename = "Networking Programs",
  severity = $(SIG_HI),
  emailto = bob@domain.com;sam@domain.com
)


Once a new signed policy file is generated from the /etc/tripwire/twpol.txt file, the specified email addresses will be notified upon violations of that particular rule. For instructions on signing your policy file, see the section called Updating the Policy File.
==Test e-mail message==
Sending Test Email Messages


To make sure that Tripwire's email notification configuration can actually send email correctly, use the following command:
Untuk mentest notifikasi e-mail kita dapat mengunakan perintah berikut


/usr/sbin/tripwire --test --email your@email.address
/usr/sbin/tripwire --test --email your@email.address
 
A test email will immediately be sent to the email address by the tripwire program.


Test [[e-mail]] akan dikirim langsung ke e-mail address oleh tripwire


==Referensi==
==Referensi==

Revision as of 03:13, 24 January 2011

Kita dapat melaporkan kejadian menggunakan tripwire dan ini harus ditulis pada file Tripwire

/etc/tripwire/twpol.txt

contoh e-mail admin bob@domain.com;sam@domain.com

(
  rulename = "Networking Programs",
  severity = $(SIG_HI),
  emailto = bob@domain.com;sam@domain.com
)


Test e-mail message

Untuk mentest notifikasi e-mail kita dapat mengunakan perintah berikut

/usr/sbin/tripwire --test --email your@email.address

Test e-mail akan dikirim langsung ke e-mail address oleh tripwire

Referensi

Pranala Menarik