bookmark_borderOSSEC v2.3 BETA1 available

OSSEC v2.3 BETA1 is now available and we need testers. You can find information on how to help us at

If you ever wanted to contribute to OSSEC (or to any open source project) that’s the easiest way to get involved. Just download the BETA, check if everything still works, if you have time try out some of the new features and let us know how it goes. You can submit your feedback in here, via the wiki, to the mailing list or personally to me via email.

We appreciate any feedback.

bookmark_borderProcess monitoring with OSSEC

We love logs. Inside OSSEC we treat everything as if it was a log and parse it appropriately with our rules. However, some information is not available in log files but we still want to monitor them. To solve that gap, we added the ability to monitor the output of commands via OSSEC and treat those just like they were log files.

For example, if you wanted to monitor the disk space utilization, you would need to setup a cron job to dump the output of “df -h” to a log file (maybe /var/log/df.log) and configure OSSEC to look at it.

*use the latest snapshot if you want to try it out:

Now, with the new version of OSSEC you can do it directly in there with the following configuration:

<command>df -h</command>

Since we already have a sample rule for df -h included into OSSEC you would see the following when any partition reached 100%:

** Alert 1257451341.28290: mail – ossec,low_diskspace,
2009 Nov 05 16:02:21 (home-ubuntu)>df -h
Rule: 531 (level 7) -> ‘Partition usage reached 100% (disk space monitor).’
Src IP: (none)
User: (none)
ossec: output: ‘df -h’: /dev/sdb1 24G 12G 11G 100% /var/backup

Another example, if you want to monitor the load average, you can configure OSSEC to monitor the “uptime” command and alert when it is higher than 2, for example:


And in the rule:

<rule id=”100101″ level=”7″ ignore=”7200″>
<match>ossec: output: ‘uptime’: </match>
<regex>load averages: 2.</regex>
<description>Load average reached 2..</description>

Lots of possibilities with this feature. If you have ideas of commands to monitor and rules, please comment.