• Support
  • Forums
  • Blogs
A New Community Experience is Coming! For more information, please see our announcement.

How to generate a rule to create an event and alert in AlienVault if a enabled plug-in is disabled?

InfoSec_PInfoSec_P

New Life Form
I am trying to create a rule that will generate a event and alert if any of the enabled plug-in in the sensor is disabled. Is there any way we can create it?
What are my option? Please let me know if you need more information.
Tagged:

Share post:

Answers

  • Any ideas or suggestion? Please advice.
  • I am thinking to Jailbreak and use python scripts to trigger a email with the list of existing plugin in the config.cfg file, if there is no option to create a rule.
  • I didn't know you could jailbreak USM anywhere to that extent.  Is there a built-in HIDS agent on that box?  If it were the USM appliance, I would just add /etc/ossim/agent/config.cfg to the hids change detection.

    Good luck.
Sign In or Register to comment.