My ideal solution for tripwire reports would be:
Daily e-mails would only generate if a violation was found
Every Sunday, a report would be e-mailed regardless of whether a violation was found
I'm also interested in the opinions of SF'ers about implementing this. Perhaps it goes against the purpose of tripwire? I could see someone making that argument I suppose.
My solution to getting a lot of tripwire reports from a lot of hosts is to have them all sent to an address which stacks them up in a file, then run a simple job on them that reports just the host name and violation counts, and only emails that report if there are any hosts with a non-zero violation count.
Firstly, all the hosts send their reports to the address
[email protected]
. That's easy to arrange from each of the crontab entries; I do it with:Secondly, on the mail server, I have an aliases entry that says:
Thirdly, I have a cron job that runs every morning to process the contents of that file, and another that runs every evening to remove it (so I'm only looking at the most recent outputs):
And here's the contents of /usr/local/bin/tripwire-check; it's very simple:
The first grep exits without any mail or output IFO all the lines that contain a violation count also contain the number 0, as a whole word; the second, which is only invoked if the first line fails, produces the terse summary email and sends it to me.
And finally, here's a sample output when there's an error to report:
Hope that's of some use.
Tripwire has an option to suppress reports that have no errors (MAILNOVIOLATIONS), it is found in the config file...
You could set up 2 different twcfg files, one with MAILNOVIOLATIONS set to TRUE, and one with this option set to FALSE
Then your cronjob could run tripwire using the -c flag to select the twcfg file
Daily report crontab:
Sunday report crontab:
This way, your daily cronjob would run tripwire using the config file that only emails reports if violations are found, and your weekly cronjob would email you a report regardless.
p.s. the above crontab commands are from a system using Debian, you may need to edit the path to your Tripwire binary.
I know I already chose Mr. MadHatter's submission as the answer but after some thinking, I've thought of something else that might work. Does anyone see why this would not work?
I've tested it out in the shell and it works as intended. However, I have not replaced the tripwire cron job yet.
What do you guys think?
Another possible simple solution, not exactly what is being asked but possible useful for someone.
Simply send the number of "Total violations found" in the subject of the mail, so I keep receiving the notifications, but I don't have the need to open them although I see some violation is happening. That way I'm also sure tripwire keeps working as expected:
Step by step:
1.- I save in the file "twreport" the tripwire report
2.- I do a grep on the twreport file for the line "Total violations found". I insert this in the subject of the mail command. And I get the twreport text contents in the body of the mail:
3.- Finally I remove the twreport file: