Ad Widget

Collapse

File integrity Query

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • syd
    Junior Member
    • Dec 2008
    • 8

    #1

    File integrity Query

    Hi,

    I've configured Zabbix to check the integrity of some file like /etc/passwd. Now when I add a new user, the trigger get activated and I get an alert.

    Now assuming that this was a valid change how do I configure this new md5 checksum to be the new baseline and generate alerts for any furthur changes

    Currently I assume that with the addition of user a alert would be generated and subsequent additions would not generate further alerts till those users are deleted and the file returns to the original md5 checksum. This is just an instance which I've explained and could apply to other files as well

    Assistance appreciated

    ----Syd
  • Alexei
    Founder, CEO
    Zabbix Certified Trainer
    Zabbix Certified SpecialistZabbix Certified Professional
    • Sep 2004
    • 5654

    #2
    You need a trigger which compares previous and current check sums of the file. I believe a trigger "File was modified" {host:cksum[/etc/passwd"].diff(0)}=1 is what you are looking for.
    Alexei Vladishev
    Creator of Zabbix, Product manager
    New York | Tokyo | Riga
    My Twitter

    Comment

    • syd
      Junior Member
      • Dec 2008
      • 8

      #3
      Thanx Alexei. It's done the job for me :-)

      Comment

      Working...