業務用エアコン関連の技術情報、エラーコード、環境問題対策に関する別サイト「エアコンの安全な修理・適切なフロン回収」

OpenSUSE15.6 : Tripwire, Logwatch Install

1. Tripwire

Tripwire is a host-based intrusion detection system (IDS) that monitors files and directories and notifies you when changes are made.

1.1 Install and configuration

① Download,Install

② Passphrase Settings

③ Tripwire Configuration

④ Create a Tripwire configuration file (cryptographically signed version)

⑤Delete Tripwire configuration file (text version)

Reference) To restore the Tripwire configuration file (text version), execute the following command

⑥ Policy File Settings

Contents of twpolmake.txt

⑦ Policy File Optimizations

⑧ Create policy file (cryptographically signed version) based on optimized policy file

Delete policy file (text version)

⑨ Create database and check operation

Create test files

Check Tripwire operation

If successful, the following will be displayed

Delete test files

1.2 Run Tripwire regularly

①Creation of auto-execution scripts

# cd /srv/www/system
# vi tripwire.sh

Contents of "tripwire.sh"
Enter the local passphrase and site passphrase set in "xxxxxxxx" for LOCALPASS and SITEPASS respectively in the passphrase settings.

②Add to cron to have Tripwire run periodically

Reference: Script for reporting results by e-mail

Execute the following command and confirm that the notification is delivered to the specified e-mail address

2. Logwatch

① Logwatch Install

② Edit configuration file

③ Output Logwatch reports

④ Test to see if the report is delivered to the address you set.