This guide presents a step-by-step tutorial on how to install OSSEC Agent on CentOS 8. OSSEC is an Open Source Host based Intrusion Detection System that performs log analysis, integrity checking, Windows registry monitoring, rootkit detection, real-time alerting and active response. It runs across multiple platforms including Linux, OpenBSD, FreeBSD, Mac OS X, Solaris and Windows etc.
Table of Contents
Install OSSEC Agent on CentOS 8
In this demo, we are going learn how to install OSSEC agent on CentOS 8 from source file.
Run system Update
Before you proceed with installation, run system update.
Install Required Build Tools
A successful installation of OSSEC on CentOS 8 requires quite a number of dependencies to be installed on the system. Run the command below to install these dependencies.
dnf install gcc make libevent-devel zlib-devel openssl-devel pcre2-devel wget tar -y
Download Latest OSSEC Source Code
OSSEC 3.6 is the latest stable release as of this writing. Check the releases page for the latest releases.
Extract OSSEC Source Code
Once the OSSEC source download is completed, extract it as follows;
tar xzf 3.6.0.tar.gz
Install OSSEC Agent on CentOS 8
To install OSSEC agent, navigate to the source code directory and run the installation script.
Execute the installation group;
Select you installation language. In this case, we choose the default install language, English.
Press ENTER to choose default installation options.
(en/br/cn/de/el/es/fr/hu/it/jp/nl/pl/ru/sr/tr) [en]: ENTER
Again, press ENTER to continue.
-- Press ENTER to continue or Ctrl-C to abort. --
Specify the type of installation. In our case, we are installing ossec-hids
agent, hence select agent.
1- What kind of installation do you want (server, agent, local, hybrid or help)? agent
- Agent(client) installation chosen.
Choose the installation path. We go with the default,
2- Setting up the installation environment.
- Choose where to install the OSSEC HIDS [/var/ossec]:
- Installation will be made at /var/ossec .
Enter the OSSEC-HIDs Server IP address or hostname. Replace the IP used here accordingly.
3- Configuring the OSSEC HIDS.
3.1- What's the IP Address or hostname of the OSSEC HIDS server?: 192.168.56.11
- Adding Server IP 192.168.56.11
Enable system integrity check
3.2- Do you want to run the integrity check daemon? (y/n) [y]: y
- Running syscheck (integrity check daemon).
Enable rootkit detection engine.
3.3- Do you want to run the rootkit detection engine? (y/n) [y]:
- Running rootcheck (rootkit detection).
Disable active response. Otherwise, you can enable it if you an understanding of the type and number of alerts you want.
3.4 - Do you want to enable active response? (y/n) [y]: n
- Active response disabled.
The agent installer then displays the log files that are read by default. You can add more later on
3.5- Setting the configuration to analyze the following logs:
Once you are done defining the default options, proceed to install OSSEC agent on CentOS 8 by pressing ENTER.
Connect the OSSEC Agent to OSSEC Server
For the agent to communicate with the server, you can need to first add it to the server.
After that extract the agent authentication key from the server.
Once you have extracted the key, Import the key on the agent by running the command below;
Enter option I, paste the key and confirm adding the key. Then type Q and press enter to exit.
Running OSSEC Agent
Once the installation completes, the installer displays how to run OSSEC agent.
To start the agent;
systemctl start ossec
To stop the agent;
systemctl stop ossec
Other unit service control commands;
You have successfully installed OSSEC agent on CentOS 8 and that marks the end of our guide on how to install OSSEC agent on CentOS 8. Stay connected for more similar tutorials.