1752770 Members
5068 Online
108789 Solutions
New Discussion юеВ

HIDS Template Creation

 
SOLVED
Go to solution
Andrew Pollard
Super Advisor

HIDS Template Creation

Hi,

I'm just learning HIDS and I am wondering if it is possible to:
1)Create my own templates
2)Create a template that will monitor the "kill" command

Any information will be a great help.

Thanks
Andrew
3 REPLIES 3
Pierre Pasturel
Respected Contributor

Re: HIDS Template Creation

Andrew -

The answer to both those questions is no.

1) What kind of templates did you have in mind?
2) Why monitor this command?

Pierre
Andrew Pollard
Super Advisor

Re: HIDS Template Creation

Hi,

The reason I wanted to know about creating templates was that I wasn't sure if the templates provided will cover all our needs, whatever they would be.

I do have another question:
I setup a Test Schedule, a Test Surveillence Group, and assigned 2 basic templates that I edited to monitor specific files and directories. I let it run for 2 days and checked it today and the templates in the Surveillence Group had changed to Race Conditions and Buffer Overflow, and the editing I did to the templates I wanted were gone.
Is there a special way to save my changes? They saved fine and ran fine on the day I did them, what would have changed?

Thanks
Andrew
Pierre Pasturel
Respected Contributor
Solution

Re: HIDS Template Creation

Andrew-

When you select your Surveillance Schedule in the Schedule Manager window, the corresponding Test Group will be checkmarked but (unforunately) will not also be highlighted. Instead, the AdvancedGroup group is highlighted, which contains the race condition and buffer overflow templates.

You need to explicitly highlight (by clicking on the Test Group name), after which you should see your customizations.

If you activate your Test schedule, you should see the correct templates and settings in /var/opt/ids/schedule on your agent host(s).

Pierre