Discussion:
[Aide] AIDE on server - AIDE on laptop
Reiner Rusch
2007-03-05 14:44:41 UTC
Permalink
Hi,

I'm new to aide but testet a bit.
So, while this software is not very difficult to understand, I'm wondering how
others configure their aide.

I installed aide on my laptop and some servers.
So, while I restart my laptop every day , a server wouldn't.
In this way, aide should be configured in different ways.

On my laptop some files below /etc differs every reboot. This seems to be at
least things according dhcp.

But on a server? Perhaps (I'm not sure) it would be interesting, to test even
those things below /etc so I know that my server was restarted, which could
be a hint....

Could anyone give me some information about their conf-files and what you do,
if aide finds differences? By now I take a sms-service to know the status
(only an alarm) once a day.
Would be nice, if you tell something about your linux-version and on what kind
of computer you installed aide (see my opinion laptop<->server).
Last question: does aide exists also for windows?

Best regards,
R.Rusch
Thomas Leveille
2007-03-06 11:05:34 UTC
Permalink
Post by Reiner Rusch
But on a server? Perhaps (I'm not sure) it would be interesting, to test even
those things below /etc so I know that my server was restarted, which could
be a hint....
Could anyone give me some information about their conf-files and what you do,
if aide finds differences? By now I take a sms-service to know the status
(only an alarm) once a day.
AIDE is meant to verify files, in order to detect intrusions. What you
are looking for is a monitoring tool for your servers, which is a
different thing :

a few interesting links :
http://www.nagios.org/ < I personnaly use it to monitor +100 servers.
http://www.tildeslash.com/monit/
http://www.zabbix.com/
http://www.hyperic.com/
http://www.groundworkopensource.com/

--
Thomas Leveille
Reiner Rusch
2007-03-06 11:50:27 UTC
Permalink
Hi Thomas,
Post by Thomas Leveille
Post by Reiner Rusch
But on a server? Perhaps (I'm not sure) it would be interesting, to test
even those things below /etc so I know that my server was restarted,
which could be a hint....
Could anyone give me some information about their conf-files and what you
do, if aide finds differences? By now I take a sms-service to know the
status (only an alarm) once a day.
AIDE is meant to verify files, in order to detect intrusions. What you
are looking for is a monitoring tool for your servers, which is a
hmm, I think aide is the right thing because I want to detect an intrusion.
But as I described some file change after new boot which is no attack to this
files.
Post by Thomas Leveille
http://www.nagios.org/ < I personnaly use it to monitor +100 servers.
http://www.tildeslash.com/monit/
http://www.zabbix.com/
http://www.hyperic.com/
http://www.groundworkopensource.com/
I know nagios but thanks for the rest!

Reiner

Loading...