|
|
|
|
| Templates and Alerts |
|
|
|
| Repeated Failed su Commands Template | |
Table | Repeated Failed Su Attempts Alert Properties (Continued) | ||||
|
|
|
|
|
|
| Response | Alert | Alert |
|
|
| Program | Field | Alert Value/Format | Description | |
| Field | ||||
| Argument | Type |
|
| |
|
|
|
| ||
|
|
|
|
|
|
| argv[4] | UTC | Integer | <secs> | UTC time in number of |
|
| Time |
|
| seconds since epoch when |
|
|
|
|
| more than |
|
|
|
|
| <max_failed_su> number |
|
|
|
|
| of failed su attempts are |
|
|
|
|
| detected for a particular |
|
|
|
|
| user. |
|
|
|
|
|
|
| argv[5] | <empty> | n/a | User <username> had more than | This field is empty |
|
|
|
| <max_failed_su> failed su attempts |
|
|
|
|
| in the past <number> [second |
|
|
|
|
| minute hour day week]. Targets |
|
|
|
|
| were [ "<username>" "<username>" |
|
|
|
|
| .... ] |
|
|
|
|
|
|
|
| argv[6] | <empty> | n/a | n/a | This field is empty |
|
|
|
|
|
|
| argv[7] | Summary | String | “Failed su attempts” | Alert summary |
|
|
|
|
|
|
| argv[8] | Details | String | “User <username> had more than | Detailed alert description |
|
|
|
| <max_failed_su> failed su attempts |
|
|
|
|
| in the past <value> days. Targets |
|
|
|
|
| were ["username”, |
|
|
|
|
|
|
|
| argv[9] | Local | Integer | <secs> | Local time in number of |
|
| Time |
|
| seconds since epoch when |
|
|
|
|
| more than |
|
|
|
|
| <max_failed_su> number |
|
|
|
|
| of failed su attempts are |
|
|
|
|
| detected for a particular |
|
|
|
|
| user. |
|
|
|
|
|
|
| argv[10] | Flag | Integer | 2 | Indicates a failed su alert |
|
|
|
|
| versus a failed login alert |
|
|
|
|
|
|
| argv[11] | Device | String | <tty> | The tty from which a |
|
|
|
|
| failed su attempt was |
|
|
|
|
| made. |
|
|
|
|
|
|
| argv[12] | From | String | <username> | The name of the user |
|
|
|
|
| attempting to su. |
|
|
|
|
|
|
| argv[13] | To | String | <username> | The target user of the last |
|
|
|
|
| failed su attempt. |
|
|
|
|
|
|
Limitations | None |
|
|
|
Appendix A | 177 |