Part 2.e: Distributing OSSIM sensor boxes

Distributing sensors to other systems:
As you may have already gathered, it’s quite easy to have sensors that are on other systems be managed, and/or output watched by the local ossim-agent.

1) If you want ossim-agent to manage remote processes, you will have to script start/stop/restart scripts that will utilize some remote execution method (such as ssh). I do not know how the ossim-agent watchdog tests to see if a process is running (then starts it if it isn’t), so this may make this process state monitoring a challenge.

2) If you want ossim-agent to simply watch a log file, obviously use something that pipes the syslogs back to machine. This can be a robust process, so I will cover it later; but I have already mentioned the use of nxlog and rsyslog a bit in previous articles.

However, this might not be the best way to handle the situation and you may want to opt to implement a family of OSSIM sensor boxes.

Configuring an OSSIM sensor box:

I will have to get back to this later. Apologies.

  1. No comments yet.
  1. No trackbacks yet.

Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

%d bloggers like this: