1834650 Members
1945 Online
110069 Solutions
New Discussion

HIDS Report

 
SOLVED
Go to solution
Andrew Pollard
Super Advisor

HIDS Report

Hi,

In order to provide Auditors with information, are there any report generating tools with HIDS?
Some reports I am looking for is:
-To show what is being monitored and what is being ignored in regards to Modification of Files/Directories, World-Writable files, Modification of another user...etc
-A quick report to show what alerts have appeared during a certain time frame.

I understand I can use files like /var/opt/ids/schedule and logs found in /var/opt/ids/gui/logs. I am just hoping that there is something more user friendly and readable.

Thanks
Andrew Pollard
2 REPLIES 2
Pierre Pasturel
Respected Contributor
Solution

Re: HIDS Report

Andrew -

Unfortunately we have no reporting facilities at this time. You would want to refer to /var/opt/ids/alert.log for the alerts that have appeared on a particular server. All entries are time stamped.

Pierre
Andrew Pollard
Super Advisor

Re: HIDS Report

Hi,

Thanks for the info.

Andrew