
Templates and Alerts
Changes to Log File Template
These properties can be used to filter out alerts generated when a particular program modifies a particular file other than appending . See “Type II: Pathnames/Programs Pairs” on page 130 for a detailed description of these property pairs.
Alerts generated • 
Append-Only  File Being Modified
This template generates and forwards the following alerts to a response program when a file is modified in a way other than being appended to:
| Table  | 
 | 
 | |||
| 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | Response | Alert | Alert Field | 
 | 
 | 
| 
 | Program | Alert Value/Format | Description | ||
| 
 | Field | Type | |||
| 
 | Argument | 
 | 
 | ||
| 
 | 
 | 
 | 
 | 
 | |
| 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | argv[1] | Template | Integer | 3 | Unique code | 
| 
 | 
 | code | 
 | 
 | assigned to | 
| 
 | 
 | 
 | 
 | 
 | template | 
| 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | argv[2] | Version | Integer | 2 | Version of the | 
| 
 | 
 | 
 | 
 | 
 | template | 
| 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | argv[3] | Severity | Integer | 2 | Severity | 
| 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | argv[4] | UTC Time | Integer | <secs> | UTC time in | 
| 
 | 
 | 
 | 
 | 
 | number of seconds | 
| 
 | 
 | 
 | 
 | 
 | since epoch when | 
| 
 | 
 | 
 | 
 | 
 | file is modified. | 
| 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | argv[5] | Attacker | String | “uid=<uid>, gid=<gid>, pid=<pid>, | The user ID, group | 
| 
 | 
 | 
 | 
 | ppid=<ppid>” | ID, process ID, | 
| 
 | 
 | 
 | 
 | 
 | and parent | 
| 
 | 
 | 
 | 
 | 
 | process ID of the | 
| 
 | 
 | 
 | 
 | 
 | process that | 
| 
 | 
 | 
 | 
 | 
 | modified the file | 
| 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | argv[6] | Target of | String | “file=<full pathname>, | The full pathname | 
| 
 | 
 | Attack | 
 | mode=<mode>,uid=<uid>,gid=<gid>, | of the file that was | 
| 
 | 
 | 
 | 
 | modified and the | |
| 
 | 
 | 
 | 
 | 
 | |
| 
 | 
 | 
 | 
 | inode=<inode>,device=<device>” | file’s mode, uid, | 
| 
 | 
 | 
 | 
 | 
 | gid, inode, and | 
| 
 | 
 | 
 | 
 | 
 | device number. | 
| 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | argv[7] | Summary | String | Alert summary | |
| 
 | 
 | 
 | 
 | potentially modified” | 
 | 
| 
 | 
 | 
 | 
 | 
 | 
 | 
| Appendix A | 153 | 
