Skip to content

Instantly share code, notes, and snippets.

@garyttierney
Created August 1, 2016 00:34
Show Gist options
  • Select an option

  • Save garyttierney/aac89f5720da7f1baa04bcd5da395f7e to your computer and use it in GitHub Desktop.

Select an option

Save garyttierney/aac89f5720da7f1baa04bcd5da395f7e to your computer and use it in GitHub Desktop.
attribute ossec_common;
type ossec_analysisd_t, ossec_common; # associate type with ossec_common
type ossec_execd_t, ossec_common;
type ossec_logcollector_t, ossec_common;
type ossec_maild_t, ossec_common;
type ossec_monitord_t, ossec_common;
type ossec_remoted_t, ossec_common;
type ossec_syscheckd_t, ossec_common;
ossec_log_filetrans(ossec_common, ossec_log_t, file)
ossec_pid_filetrans(ossec_common, ossec_var_run_t, file)
ossec_read_config(ossec_common)
sysnet_read_config(ossec_common)
ossec_log_filetrans(ossec_execd_t, ossec_log_t, file)
ossec_log_filetrans(ossec_logcollector_t, ossec_log_t, file)
ossec_log_filetrans(ossec_maild_t, ossec_log_t, file)
ossec_log_filetrans(ossec_monitord_t, ossec_log_t, file)
ossec_log_filetrans(ossec_remoted_t, ossec_log_t, file)
ossec_log_filetrans(ossec_syscheckd_t, ossec_log_t, file)
ossec_pid_filetrans(ossec_execd_t, ossec_var_run_t, file)
ossec_pid_filetrans(ossec_logcollector_t, ossec_var_run_t, file)
ossec_pid_filetrans(ossec_maild_t, ossec_var_run_t, file)
ossec_pid_filetrans(ossec_monitord_t, ossec_var_run_t, file)
ossec_pid_filetrans(ossec_remoted_t, ossec_var_run_t, file)
ossec_pid_filetrans(ossec_syscheckd_t, ossec_var_run_t, file)
ossec_read_config(ossec_analysisd_t)
ossec_read_config(ossec_execd_t)
ossec_read_config(ossec_logcollector_t)
ossec_read_config(ossec_maild_t)
ossec_read_config(ossec_monitord_t)
ossec_read_config(ossec_remoted_t)
ossec_read_config(ossec_syscheckd_t)
sysnet_read_config(ossec_analysisd_t)
sysnet_read_config(ossec_execd_t)
sysnet_read_config(ossec_logcollector_t)
sysnet_read_config(ossec_maild_t)
sysnet_read_config(ossec_monitord_t)
sysnet_read_config(ossec_remoted_t)
sysnet_read_config(ossec_syscheckd_t)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment