LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions
User Name
Password
Linux - Distributions This forum is for Distribution specific questions.
Red Hat, Slackware, Debian, Novell, LFS, Mandriva, Ubuntu, Fedora - the list goes on and on... Note: An (*) indicates there is no official participation from that distribution here at LQ.

Notices


Reply
  Search this Thread
Old 08-11-2005, 05:43 AM   #1
hinetvenkat
Member
 
Registered: Nov 2004
Location: Mumbai
Posts: 80

Rep: Reputation: 15
About tripwire


Dear all

When i configure the tripwire... twpol.txt is not updating with the emailto option. i checked the seveiority level also.. i can get the testmail through tripwire...


i am facing the problem like as follows



[root@station mail]# mail
Mail version 8.1 6/6/93. Type ? for help.
"/var/spool/mail/root": 5 messages 5 unread
>U 1 root@localhost.local Thu Aug 11 10:30 45/1795 "LogWatch for station"
U 2 root@localhost.local Thu Aug 11 10:30 86/3151 "LogWatch for station"
U 3 root@localhost.local Thu Aug 11 14:52 18/681 "hai"
U 4 root@localhost.local Thu Aug 11 15:12 18/670 "hai"
U 5 tripwire@localhost.l Thu Aug 11 15:22 20/852 "Test email message from Tripwire"
& q
Held 5 messages in /var/spool/mail/root

[root@station mail]# cd /etc/tripwire/

[root@station tripwire]# ls
site.key tw.cfg twcfg.txt tw.pol twpol.txt
station-local.key tw.cfg.11031.bak twinstall.sh tw.pol.bak

[root@station tripwire]# vi twpol.txt

[root@station tripwire]# twadmin --create-polfile -S site.key /etc/tripwire/twpol.txt
### Error: Severity value outside of allowable limits.
### 80emailto: Line number 558
### Exiting...
The policy file was not altered.
[root@station tripwire]# vi twpol.txt


If i remove the severity level in that rule, polocy file has updated. But tripwire is not send the mails to account

Kindly help me

"Everything is possible"
 
Old 08-11-2005, 09:53 PM   #2
Matir
LQ Guru
 
Registered: Nov 2004
Location: San Jose, CA
Distribution: Debian, Arch
Posts: 8,507

Rep: Reputation: 128Reputation: 128
It looks like you are missing a newline between the 80 and the emailto.
 
Old 08-11-2005, 11:13 PM   #3
hinetvenkat
Member
 
Registered: Nov 2004
Location: Mumbai
Posts: 80

Original Poster
Rep: Reputation: 15
I have to put "," for next line right, Done

(
rulename = "Operating System Utilities",
severity = 80,
emailto = root@station
)

It is working fine... Thanks
 
Old 08-12-2005, 08:47 AM   #4
Matir
LQ Guru
 
Registered: Nov 2004
Location: San Jose, CA
Distribution: Debian, Arch
Posts: 8,507

Rep: Reputation: 128Reputation: 128
No problem. Glad you got it working.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Tripwire Obie Linux - Security 2 09-23-2004 04:22 PM
tripwire help spideywebsling Linux - Security 1 07-09-2004 04:57 PM
tripwire reports /usr/sbin/tripwire changed alfaalfabeta Linux - Security 5 07-22-2003 05:52 PM
Tripwire pk21 Linux - Security 5 06-08-2003 09:43 AM
Tripwire? janderson622 Linux - Security 2 05-01-2001 12:33 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions

All times are GMT -5. The time now is 03:17 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration