Skip to content

Commit 1244e2e

Browse files
authored
Merge pull request #831 from flashcatcloud/sync/doc-cards-b17-test
Sync to test: Check Point SmartEvent, OSSEC, Zeek docs
2 parents cbaa6f2 + 92d5994 commit 1244e2e

8 files changed

Lines changed: 627 additions & 0 deletions

File tree

‎docs.json‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1828,6 +1828,9 @@
18281828
"zh/on-call/integration/alert-integration/alert-sources/loggly",
18291829
"zh/on-call/integration/alert-integration/alert-sources/papertrail",
18301830
"zh/on-call/integration/alert-integration/alert-sources/catchpoint",
1831+
"zh/on-call/integration/alert-integration/alert-sources/check-point-smartevent",
1832+
"zh/on-call/integration/alert-integration/alert-sources/ossec",
1833+
"zh/on-call/integration/alert-integration/alert-sources/zeek",
18311834
"zh/on-call/integration/alert-integration/alert-sources/zabbix",
18321835
"zh/on-call/integration/alert-integration/alert-sources/flashcat",
18331836
"zh/on-call/integration/alert-integration/alert-sources/open-falcon",
@@ -3400,6 +3403,9 @@
34003403
"en/on-call/integration/alert-integration/alert-sources/loggly",
34013404
"en/on-call/integration/alert-integration/alert-sources/papertrail",
34023405
"en/on-call/integration/alert-integration/alert-sources/catchpoint",
3406+
"en/on-call/integration/alert-integration/alert-sources/check-point-smartevent",
3407+
"en/on-call/integration/alert-integration/alert-sources/ossec",
3408+
"en/on-call/integration/alert-integration/alert-sources/zeek",
34033409
"en/on-call/integration/alert-integration/alert-sources/zabbix",
34043410
"en/on-call/integration/alert-integration/alert-sources/flashcat",
34053411
"en/on-call/integration/alert-integration/alert-sources/open-falcon",
Lines changed: 60 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,60 @@
1+
---
2+
title: "Check Point SmartEvent Alert Integration"
3+
description: "Check Point SmartEvent automatic reactions can send email. Use the Flashduty Email integration to bring SmartEvent events into Flashduty."
4+
keywords: ["alert integration", "Check Point", "SmartEvent", "email", "security events"]
5+
---
6+
7+
SmartEvent automatic reactions offer Mail, SNMP Trap, Block Source, Block Event Activity and External Script. There is no webhook. The Flashduty [Email integration](/en/on-call/integration/alert-integration/alert-sources/email) can receive SmartEvent mail, so no separate Check Point integration is needed: create an Email integration in Flashduty and use its address as the recipient of the SmartEvent Mail reaction.
8+
9+
<div className="hide">
10+
11+
## In Flashduty On-call
12+
---
13+
14+
You can get the integration email address in either of two ways. **Choose the Email integration type in both cases**, not Check Point.
15+
16+
### Dedicated integration
17+
18+
1. In the Flashduty console, go to **Channels** and open a channel
19+
2. Go to **Settings** → **Integrations** → **Dedicated integrations** and click **Add an integration**
20+
3. Select **Email** and click **Save**
21+
4. Open the generated card and copy the **Email address**
22+
23+
### Shared integration
24+
25+
1. In the Flashduty console, go to **Integration Center → Alert Events**
26+
2. Select **Email**, enter an integration name and copy the **Email address**
27+
3. Configure the default route, choose a channel and click **Save**
28+
29+
</div>
30+
31+
## Confirm the push mode in Flashduty
32+
---
33+
34+
SmartEvent sends one mail per event and no recovery mail, and the subject carries the event number (see [Mail subject format](#mail-subject-format)), so every mail is an independent event. Keep the Email integration's default push mode: each mail creates a new alert whose title is the mail subject and whose description is the mail body. No trigger or close rules are needed.
35+
36+
## In Check Point SmartConsole
37+
---
38+
39+
Paths follow the Check Point R81.10 administration guide.
40+
41+
1. In SmartConsole, click the **Logs & Monitor** view in the left navigation panel, click **+**, then under **External Apps** click **SmartEvent Settings & Policy**
42+
2. Go to **General Settings** → **Objects** → **Automatic Reactions** and click **Add** → **Mail**
43+
3. Fill in **Name** and the sender address in **From**
44+
4. In **To**, enter the address of the Flashduty Email integration (separate multiple addresses with semicolons)
45+
5. In **Outgoing mail server (SMTP)**, enter the IP address or FQDN of an SMTP server that can deliver mail to Flashduty
46+
6. Keep the default **Subject**, `[EventNumber] - [Severity] - [Name]`, so the subject carries the event number, severity and event name
47+
7. Save, reference the automatic reaction in the event definitions you want notifications for, and install the policy
48+
49+
## Mail subject format
50+
---
51+
52+
The default **Subject** of the Mail reaction is `[EventNumber] - [Severity] - [Name]`: event number, severity and event name. Flashduty uses the mail subject as the alert title.
53+
54+
## Limitations
55+
---
56+
57+
- **No recovery**: SmartEvent sends no recovery mail. Enable [auto-resolve timeout](/en/on-call/channel/create-edit) on the channel that receives this integration (24 hours suggested), or close alerts manually in Flashduty.
58+
- **No deduplication**: the subject contains the event number, so each event creates its own alert.
59+
- **Severity**: alerts from the Email integration always have Warning severity. Use an [alert processing pipeline](/en/on-call/integration/alert-integration/alert-pipelines) to adjust it from the severity text in the subject.
60+
- **Integration type**: alerts show Email as the integration type in Flashduty.
Lines changed: 138 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,138 @@
1+
---
2+
title: "OSSEC Alert Integration"
3+
description: "OSSEC sends alert notifications by email. Use the Flashduty Email integration to bring OSSEC alerts into Flashduty On-call."
4+
keywords: ["alert integration", "OSSEC", "OSSEC HIDS", "HIDS", "intrusion detection", "email", "security alerts"]
5+
---
6+
7+
The OSSEC server (ossec-maild) can send alerts by email to the recipients you configure. The Flashduty [Email integration](/en/on-call/integration/alert-integration/alert-sources/email) receives these emails, so no separate OSSEC integration is needed: create an Email integration in Flashduty, put its address in OSSEC as the recipient, and choose the push mode described below.
8+
9+
<div className="hide">
10+
11+
## In Flashduty On-call
12+
---
13+
14+
You can get the integration email address in either of the two ways below. **Choose Email as the integration type** in both cases, not OSSEC.
15+
16+
### Dedicated integration
17+
18+
1. Go to the Flashduty console, select **Channels**, and open a channel
19+
2. Go to **Settings** → **Integrations** → **Dedicated integrations** and click **Add an integration**
20+
3. Select **Email** and click **Save**
21+
4. Open the generated integration card, copy the **Email address**, then set the push mode as described below
22+
23+
### Shared integration
24+
25+
1. Go to the Flashduty console and select **Integration Center → Alert events**
26+
2. Select **Email**, enter an integration name, and copy the **Email address**
27+
3. Set the push mode as described below
28+
4. Configure the default route, select a channel, and click **Save**
29+
30+
</div>
31+
32+
## Configure the push mode in Flashduty
33+
---
34+
35+
OSSEC sends one email when an alert is generated and never sends a recovery email, so no "close alert" rule is needed. Set **Push Mode** to **Trigger or Update Alert Based on Email Subject**: emails with the same title (same host, same log source, same level, same rule description) are merged into the one open alert, and emails with different titles each create a separate alert.
36+
37+
The title format is described in [Email subject format](#email-subject-format).
38+
39+
OSSEC does not send recovery notifications. Enable [auto-resolve timeout](/en/on-call/channel/create-edit) on the channel that receives this integration, with a suggested window of 24 hours, or close alerts manually once handled.
40+
41+
## Configure OSSEC
42+
---
43+
44+
All configuration below is done in `/var/ossec/etc/ossec.conf` on the OSSEC server. Agents need no configuration because alerts are generated only on the server.
45+
46+
<Steps>
47+
<Step title="Configure email delivery">
48+
49+
In `<global>`, set the recipient, SMTP server, and sender. Set the **recipient** to the address of the Flashduty Email integration:
50+
51+
```xml
52+
<ossec_config>
53+
<global>
54+
<email_notification>yes</email_notification>
55+
<email_to>YOUR_FLASHDUTY_EMAIL_ADDRESS</email_to>
56+
<smtp_server>mx.example.com</smtp_server>
57+
<email_from>ossec@example.com</email_from>
58+
</global>
59+
</ossec_config>
60+
```
61+
62+
Consumer and hosted providers such as Gmail and Outlook.com generally do not accept unauthenticated relay. If your SMTP server requires authentication or TLS, follow the SMTP-authenticated email section of the OSSEC documentation.
63+
64+
</Step>
65+
66+
<Step title="Set the minimum alert level for email">
67+
68+
```xml
69+
<ossec_config>
70+
<alerts>
71+
<email_alert_level>10</email_alert_level>
72+
</alerts>
73+
</ossec_config>
74+
```
75+
76+
Only alerts whose rule level is greater than or equal to this value are emailed. Choose a value that matches what your SOC can handle so low-level alerts do not bury on-call responders.
77+
78+
</Step>
79+
80+
<Step title="Avoid merging several alerts into one email (optional)">
81+
82+
By default OSSEC batches alerts that arrive close together into a single email, and the subject reflects only one of them, so Flashduty cannot create one alert per OSSEC alert. To send each alert as its own email, add an `<email_alerts>` block for the same recipient with `<do_not_group />` and `<do_not_delay />` (the `<global>` section must already contain at least one `<email_to>`):
83+
84+
```xml
85+
<ossec_config>
86+
<email_alerts>
87+
<email_to>YOUR_FLASHDUTY_EMAIL_ADDRESS</email_to>
88+
<level>10</level>
89+
<do_not_delay />
90+
<do_not_group />
91+
</email_alerts>
92+
</ossec_config>
93+
```
94+
95+
`<email_alerts>` also accepts `<group>`, `<rule_id>` (comma-separated), and `<event_location>` to narrow which alerts are forwarded.
96+
97+
</Step>
98+
99+
<Step title="Restart and verify">
100+
101+
```bash
102+
/var/ossec/bin/ossec-control restart
103+
```
104+
105+
1. Trigger an alert at or above the email level on a monitored host, for example by entering wrong passwords repeatedly against SSH
106+
2. Confirm in Flashduty that an alert arrives, titled with the OSSEC email subject
107+
3. If nothing arrives, check `/var/ossec/logs/ossec.log` on the OSSEC server for SMTP errors
108+
109+
</Step>
110+
</Steps>
111+
112+
## Email subject format
113+
---
114+
115+
OSSEC emails use the full subject by default (internal option `maild.full_subject=0`, the default value):
116+
117+
```
118+
OSSEC Alert - <location> - Level <level> - <rule description>
119+
```
120+
121+
Example:
122+
123+
```
124+
OSSEC Alert - (slacker) 192.168.2.0 - Level 3 - SSHD authentication success.
125+
```
126+
127+
The location is "(agent name) agent IP", or the server name for alerts from the server itself. The log file path after `->` is not included in the subject. The subject is limited to 127 characters, so a long rule description is truncated.
128+
129+
The email body starts with `OSSEC HIDS Notification.`, followed by the alert time, `Received From` (the alert source), `Rule: <rule ID> fired (level <level>) -> "<rule description>"`, the source IP / user when present, and the triggering log excerpt (`Portion of the log(s)`). In Flashduty, the alert title is the email subject and the description is the email body.
130+
131+
## Limitations
132+
---
133+
134+
- **No recovery**: an OSSEC alert is a one-time event. Alerts in Flashduty do not resolve automatically; rely on [auto-resolve timeout](/en/on-call/channel/create-edit) or close them manually.
135+
- **Severity**: the Email integration sets every alert to Warning. The subject carries the OSSEC level (`Level N`), so you can adjust severity by level with an [Alert Pipeline](/en/on-call/integration/alert-integration/alert-pipelines).
136+
- **No rule ID in the subject**: the subject has the rule description only, so alerts from different rules that share the same description, location, and level are merged. The rule ID is in the email body.
137+
- **Sensitive data**: the body contains a raw log excerpt that may include usernames, IPs, and file paths. Filter with `<email_alert_level>` or the `<group>` and `<rule_id>` options of `<email_alerts>` and avoid forwarding raw authentication logs.
138+
- **Merging**: emails with the same subject merge into the same open alert; once that alert is closed, a new email creates a new alert.
Lines changed: 111 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,111 @@
1+
---
2+
title: "Zeek alert integration"
3+
description: "Zeek's Notice framework can send notices by email; use a Flashduty email integration to bring Zeek notices into Flashduty."
4+
keywords: ["alert integration", "Zeek", "Bro", "Notice", "email", "network security monitoring", "NDR"]
5+
---
6+
7+
Zeek records detections as notices through its Notice framework, and the `Notice::ACTION_EMAIL` action sends each notice as one email. It has no webhook. The Flashduty [email integration](/en/on-call/integration/alert-integration/alert-sources/email) receives these emails, so no separate Zeek integration is needed: create an email integration in Flashduty and set its email address as the Zeek notice recipient.
8+
9+
<div className="hide">
10+
11+
## In Flashduty On-call
12+
---
13+
14+
Get the integration email address in either of the two ways below. **In both cases choose the Email integration type**, not Zeek.
15+
16+
### Use a dedicated integration
17+
18+
1. In the Flashduty console, select **Channels** and open a channel
19+
2. Select **Settings** → **Integrations** → **Dedicated integrations** and click **Add an integration**
20+
3. Select **Email** and click **Save**
21+
4. Open the new integration card, copy the **email address**, then configure Zeek as described below
22+
23+
### Use a shared integration
24+
25+
1. In the Flashduty console, select **Integration Center → Alert events**
26+
2. Select **Email**, enter an integration name and copy the **email address**
27+
3. Configure Zeek as described below
28+
4. Set a default route, select a channel and click **Save**
29+
30+
</div>
31+
32+
## Configure the push mode in Flashduty
33+
---
34+
35+
Zeek notice emails only trigger; there is no resolve email, so no rules are needed to close alerts. Keep the email integration's default push mode, which creates a new alert for every email.
36+
37+
- The alert title is the email title, for example `[Zeek] SSH::Password_Guessing` (bracketed prefix plus the notice type)
38+
- The alert description is the email body, with the notice message, the source and destination addresses and ports of the connection, and so on
39+
- Severity is always Warning; adjust it by notice type with [alert pipelines](/en/on-call/integration/alert-integration/alert-pipelines)
40+
41+
Zeek already suppresses repeats of the same notice for `suppress_for` (1 hour by default), so merging in Flashduty is usually unnecessary. To merge notices of the same type into one alert, switch the push mode to **Trigger or Update Alert Based on Email Subject**. The title holds only the notice type, so notices of the same type from different hosts merge together.
42+
43+
## Configure Zeek
44+
---
45+
46+
### Recipient and mailer (ZeekControl)
47+
48+
Set these options in the ZeekControl configuration file `zeekctl.cfg`, then run `zeekctl deploy`:
49+
50+
| Option | Description |
51+
| :--- | :--- |
52+
| `MailTo` | Recipient for non-summary emails; enter the Flashduty email integration address. Overrides the Zeek script variable `Notice::mail_dest` |
53+
| `SendMail` | Path of the sendmail binary. Leave it empty and no email is sent, so make sure the host can send mail with sendmail |
54+
| `MailFrom` | Sender, `Zeek <zeek@localhost>` by default; change as needed |
55+
| `MailSubjectPrefix` | Email title prefix, `[Zeek]` by default |
56+
57+
Without ZeekControl, set `Notice::mail_dest`, `Notice::mail_from` and `Notice::sendmail` in a Zeek script; they mean the same.
58+
59+
### Choose which notices are emailed
60+
61+
Zeek emails only notices that have the `Notice::ACTION_EMAIL` action applied. In `local.zeek`, select notice types with `Notice::emailed_types`:
62+
63+
```zeek
64+
redef Notice::emailed_types += {
65+
SSH::Password_Guessing,
66+
SSL::Invalid_Server_Cert,
67+
};
68+
```
69+
70+
You can also add the action conditionally in a `Notice::policy` hook and set the recipient directly:
71+
72+
```zeek
73+
hook Notice::policy(n: Notice::Info)
74+
{
75+
if ( n$note == SSH::Password_Guessing )
76+
{
77+
add n$actions[Notice::ACTION_EMAIL];
78+
n$email_dest = set("<Flashduty email integration address>");
79+
}
80+
}
81+
```
82+
83+
Redeploy Zeek (`zeekctl deploy`) for the change to take effect.
84+
85+
## Email format
86+
---
87+
88+
A single-notice email (`Notice::ACTION_EMAIL`) has the title `Notice::mail_subject_prefix` (`[Zeek]` by default), a space, then the notice type. The body is made of the parts below:
89+
90+
```
91+
Subject: [Zeek] SSH::Password_Guessing
92+
93+
Message: 192.168.56.1 appears to be guessing SSH passwords (seen in 10 connections).
94+
Sub-message: Sampled servers: 192.168.56.103, 192.168.56.103
95+
96+
Connection: 192.168.56.1:51234 -> 192.168.56.103:22
97+
Connection uid: CXWv6p3arKYeMETxOg
98+
```
99+
100+
- `Message` is the notice message; `Sub-message` is extra detail and appears only when the notice has one
101+
- A notice tied to a connection has `Connection` and `Connection uid`; one tied only to an address has `Address`
102+
- A notice with file information also has `File Description` and `File MIME Type`
103+
- Content that scripts add through `email_body_sections` is appended at the end of the body
104+
105+
## Limitations
106+
---
107+
108+
- **Trigger only, no resolve**: Zeek never sends a resolve email. Turn on the [auto-resolve timeout](/en/on-call/channel/create-edit) in the channel that receives this integration; 24 hours is a reasonable start. Otherwise alerts must be closed manually.
109+
- **Summary emails**: `Notice::ACTION_ALARM` does not send one email per notice. It bundles the `notice_alarm` log on a schedule (`MailAlarmsInterval` in ZeekControl, 86400 seconds by default) into one summary email titled like `[Zeek] Log Contents: ...`, which holds several notices and creates a single alert. Use `Notice::ACTION_EMAIL` when you need one alert per notice.
110+
- **Title has no detail**: the email title holds only the notice type; hosts, addresses and other details are in the body, so read the alert description in Flashduty.
111+
- **Severity**: Zeek notices have no severity field, so alert severity is always Warning.

‎integration-docs/src/doc-map.mjs‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -221,6 +221,9 @@ export const docMap = {
221221
Loggly: `${alertBase}/loggly.mdx`,
222222
Papertrail: `${alertBase}/papertrail.mdx`,
223223
Catchpoint: `${alertBase}/catchpoint.mdx`,
224+
CheckPointSmartEvent: `${alertBase}/check-point-smartevent.mdx`,
225+
Ossec: `${alertBase}/ossec.mdx`,
226+
Zeek: `${alertBase}/zeek.mdx`,
224227
MonteCarlo: `${alertBase}/monte-carlo.mdx`,
225228
Limacharlie: `${alertBase}/limacharlie.mdx`,
226229
Last9: `${alertBase}/last9.mdx`,

0 commit comments

Comments
 (0)