|
| 1 | +--- |
| 2 | +title: "OSSEC Alert Integration" |
| 3 | +description: "OSSEC sends alert notifications by email. Use the Flashduty Email integration to bring OSSEC alerts into Flashduty On-call." |
| 4 | +keywords: ["alert integration", "OSSEC", "OSSEC HIDS", "HIDS", "intrusion detection", "email", "security alerts"] |
| 5 | +--- |
| 6 | + |
| 7 | +The OSSEC server (ossec-maild) can send alerts by email to the recipients you configure. The Flashduty [Email integration](/en/on-call/integration/alert-integration/alert-sources/email) receives these emails, so no separate OSSEC integration is needed: create an Email integration in Flashduty, put its address in OSSEC as the recipient, and choose the push mode described below. |
| 8 | + |
| 9 | +<div className="hide"> |
| 10 | + |
| 11 | +## In Flashduty On-call |
| 12 | +--- |
| 13 | + |
| 14 | +You can get the integration email address in either of the two ways below. **Choose Email as the integration type** in both cases, not OSSEC. |
| 15 | + |
| 16 | +### Dedicated integration |
| 17 | + |
| 18 | +1. Go to the Flashduty console, select **Channels**, and open a channel |
| 19 | +2. Go to **Settings** → **Integrations** → **Dedicated integrations** and click **Add an integration** |
| 20 | +3. Select **Email** and click **Save** |
| 21 | +4. Open the generated integration card, copy the **Email address**, then set the push mode as described below |
| 22 | + |
| 23 | +### Shared integration |
| 24 | + |
| 25 | +1. Go to the Flashduty console and select **Integration Center → Alert events** |
| 26 | +2. Select **Email**, enter an integration name, and copy the **Email address** |
| 27 | +3. Set the push mode as described below |
| 28 | +4. Configure the default route, select a channel, and click **Save** |
| 29 | + |
| 30 | +</div> |
| 31 | + |
| 32 | +## Configure the push mode in Flashduty |
| 33 | +--- |
| 34 | + |
| 35 | +OSSEC sends one email when an alert is generated and never sends a recovery email, so no "close alert" rule is needed. Set **Push Mode** to **Trigger or Update Alert Based on Email Subject**: emails with the same title (same host, same log source, same level, same rule description) are merged into the one open alert, and emails with different titles each create a separate alert. |
| 36 | + |
| 37 | +The title format is described in [Email subject format](#email-subject-format). |
| 38 | + |
| 39 | +OSSEC does not send recovery notifications. Enable [auto-resolve timeout](/en/on-call/channel/create-edit) on the channel that receives this integration, with a suggested window of 24 hours, or close alerts manually once handled. |
| 40 | + |
| 41 | +## Configure OSSEC |
| 42 | +--- |
| 43 | + |
| 44 | +All configuration below is done in `/var/ossec/etc/ossec.conf` on the OSSEC server. Agents need no configuration because alerts are generated only on the server. |
| 45 | + |
| 46 | +<Steps> |
| 47 | +<Step title="Configure email delivery"> |
| 48 | + |
| 49 | +In `<global>`, set the recipient, SMTP server, and sender. Set the **recipient** to the address of the Flashduty Email integration: |
| 50 | + |
| 51 | +```xml |
| 52 | +<ossec_config> |
| 53 | + <global> |
| 54 | + <email_notification>yes</email_notification> |
| 55 | + <email_to>YOUR_FLASHDUTY_EMAIL_ADDRESS</email_to> |
| 56 | + <smtp_server>mx.example.com</smtp_server> |
| 57 | + <email_from>ossec@example.com</email_from> |
| 58 | + </global> |
| 59 | +</ossec_config> |
| 60 | +``` |
| 61 | + |
| 62 | +Consumer and hosted providers such as Gmail and Outlook.com generally do not accept unauthenticated relay. If your SMTP server requires authentication or TLS, follow the SMTP-authenticated email section of the OSSEC documentation. |
| 63 | + |
| 64 | +</Step> |
| 65 | + |
| 66 | +<Step title="Set the minimum alert level for email"> |
| 67 | + |
| 68 | +```xml |
| 69 | +<ossec_config> |
| 70 | + <alerts> |
| 71 | + <email_alert_level>10</email_alert_level> |
| 72 | + </alerts> |
| 73 | +</ossec_config> |
| 74 | +``` |
| 75 | + |
| 76 | +Only alerts whose rule level is greater than or equal to this value are emailed. Choose a value that matches what your SOC can handle so low-level alerts do not bury on-call responders. |
| 77 | + |
| 78 | +</Step> |
| 79 | + |
| 80 | +<Step title="Avoid merging several alerts into one email (optional)"> |
| 81 | + |
| 82 | +By default OSSEC batches alerts that arrive close together into a single email, and the subject reflects only one of them, so Flashduty cannot create one alert per OSSEC alert. To send each alert as its own email, add an `<email_alerts>` block for the same recipient with `<do_not_group />` and `<do_not_delay />` (the `<global>` section must already contain at least one `<email_to>`): |
| 83 | + |
| 84 | +```xml |
| 85 | +<ossec_config> |
| 86 | + <email_alerts> |
| 87 | + <email_to>YOUR_FLASHDUTY_EMAIL_ADDRESS</email_to> |
| 88 | + <level>10</level> |
| 89 | + <do_not_delay /> |
| 90 | + <do_not_group /> |
| 91 | + </email_alerts> |
| 92 | +</ossec_config> |
| 93 | +``` |
| 94 | + |
| 95 | +`<email_alerts>` also accepts `<group>`, `<rule_id>` (comma-separated), and `<event_location>` to narrow which alerts are forwarded. |
| 96 | + |
| 97 | +</Step> |
| 98 | + |
| 99 | +<Step title="Restart and verify"> |
| 100 | + |
| 101 | +```bash |
| 102 | +/var/ossec/bin/ossec-control restart |
| 103 | +``` |
| 104 | + |
| 105 | +1. Trigger an alert at or above the email level on a monitored host, for example by entering wrong passwords repeatedly against SSH |
| 106 | +2. Confirm in Flashduty that an alert arrives, titled with the OSSEC email subject |
| 107 | +3. If nothing arrives, check `/var/ossec/logs/ossec.log` on the OSSEC server for SMTP errors |
| 108 | + |
| 109 | +</Step> |
| 110 | +</Steps> |
| 111 | + |
| 112 | +## Email subject format |
| 113 | +--- |
| 114 | + |
| 115 | +OSSEC emails use the full subject by default (internal option `maild.full_subject=0`, the default value): |
| 116 | + |
| 117 | +``` |
| 118 | +OSSEC Alert - <location> - Level <level> - <rule description> |
| 119 | +``` |
| 120 | + |
| 121 | +Example: |
| 122 | + |
| 123 | +``` |
| 124 | +OSSEC Alert - (slacker) 192.168.2.0 - Level 3 - SSHD authentication success. |
| 125 | +``` |
| 126 | + |
| 127 | +The location is "(agent name) agent IP", or the server name for alerts from the server itself. The log file path after `->` is not included in the subject. The subject is limited to 127 characters, so a long rule description is truncated. |
| 128 | + |
| 129 | +The email body starts with `OSSEC HIDS Notification.`, followed by the alert time, `Received From` (the alert source), `Rule: <rule ID> fired (level <level>) -> "<rule description>"`, the source IP / user when present, and the triggering log excerpt (`Portion of the log(s)`). In Flashduty, the alert title is the email subject and the description is the email body. |
| 130 | + |
| 131 | +## Limitations |
| 132 | +--- |
| 133 | + |
| 134 | +- **No recovery**: an OSSEC alert is a one-time event. Alerts in Flashduty do not resolve automatically; rely on [auto-resolve timeout](/en/on-call/channel/create-edit) or close them manually. |
| 135 | +- **Severity**: the Email integration sets every alert to Warning. The subject carries the OSSEC level (`Level N`), so you can adjust severity by level with an [Alert Pipeline](/en/on-call/integration/alert-integration/alert-pipelines). |
| 136 | +- **No rule ID in the subject**: the subject has the rule description only, so alerts from different rules that share the same description, location, and level are merged. The rule ID is in the email body. |
| 137 | +- **Sensitive data**: the body contains a raw log excerpt that may include usernames, IPs, and file paths. Filter with `<email_alert_level>` or the `<group>` and `<rule_id>` options of `<email_alerts>` and avoid forwarding raw authentication logs. |
| 138 | +- **Merging**: emails with the same subject merge into the same open alert; once that alert is closed, a new email creates a new alert. |
0 commit comments