
| 
 | 
 | 
 | 
 | 
 | Templates and Alerts | 
| 
 | 
 | 
 | 
 | Repeated Failed su Commands Template | |
| Table  | Repeated Failed Su Attempts Alert Properties (Continued) | ||||
| 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | Response | Alert | Alert | 
 | 
 | 
| 
 | Program | Field | Alert Value/Format | Description | |
| 
 | Field | ||||
| 
 | Argument | Type | 
 | 
 | |
| 
 | 
 | 
 | 
 | ||
| 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | argv[4] | UTC | Integer | <secs> | UTC time in number of | 
| 
 | 
 | Time | 
 | 
 | seconds since epoch when | 
| 
 | 
 | 
 | 
 | 
 | more than | 
| 
 | 
 | 
 | 
 | 
 | <max_failed_su> number | 
| 
 | 
 | 
 | 
 | 
 | of failed su attempts are | 
| 
 | 
 | 
 | 
 | 
 | detected for a particular | 
| 
 | 
 | 
 | 
 | 
 | user. | 
| 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | argv[5] | <empty> | n/a | User <username> had more than | This field is empty | 
| 
 | 
 | 
 | 
 | <max_failed_su> failed su attempts | 
 | 
| 
 | 
 | 
 | 
 | in the past <number> [second | 
 | 
| 
 | 
 | 
 | 
 | minute hour day week]. Targets | 
 | 
| 
 | 
 | 
 | 
 | were [ "<username>" "<username>" | 
 | 
| 
 | 
 | 
 | 
 | .... ] | 
 | 
| 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | argv[6] | <empty> | n/a | n/a | This field is empty | 
| 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | argv[7] | Summary | String | “Failed su attempts” | Alert summary | 
| 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | argv[8] | Details | String | “User <username> had more than | Detailed alert description | 
| 
 | 
 | 
 | 
 | <max_failed_su> failed su attempts | 
 | 
| 
 | 
 | 
 | 
 | in the past <value> days. Targets | 
 | 
| 
 | 
 | 
 | 
 | were ["username”, | 
 | 
| 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | argv[9] | Local | Integer | <secs> | Local time in number of | 
| 
 | 
 | Time | 
 | 
 | seconds since epoch when | 
| 
 | 
 | 
 | 
 | 
 | more than | 
| 
 | 
 | 
 | 
 | 
 | <max_failed_su> number | 
| 
 | 
 | 
 | 
 | 
 | of failed su attempts are | 
| 
 | 
 | 
 | 
 | 
 | detected for a particular | 
| 
 | 
 | 
 | 
 | 
 | user. | 
| 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | argv[10] | Flag | Integer | 2 | Indicates a failed su alert | 
| 
 | 
 | 
 | 
 | 
 | versus a failed login alert | 
| 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | argv[11] | Device | String | <tty> | The tty from which a | 
| 
 | 
 | 
 | 
 | 
 | failed su attempt was | 
| 
 | 
 | 
 | 
 | 
 | made. | 
| 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | argv[12] | From | String | <username> | The name of the user | 
| 
 | 
 | 
 | 
 | 
 | attempting to su. | 
| 
 | 
 | 
 | 
 | 
 | 
 | 
| 
 | argv[13] | To | String | <username> | The target user of the last | 
| 
 | 
 | 
 | 
 | 
 | failed su attempt. | 
| 
 | 
 | 
 | 
 | 
 | 
 | 
| Limitations | None | 
 | 
 | 
 | |
| Appendix A | 177 | 
