如何用Wazuh或脚本实现Linux进程启动告警(排除自身进程)
Linux普通进程启动告警(基于Wazuh+脚本优化方案)
问题描述
我需要监控Linux进程,目前正在使用Wazuh,希望实现普通进程启动时的告警(排除服务进程),请问是否可行?
最初尝试编写Wazuh规则检测程序启动:
<local_rules> <group name="syslog,"> <rule id="9999" level="10"> <program_name>.*</program_name> <source_name>syslog</source_name> <option name="description" value="Process monitoring rule." /> </rule> </group> </local_rules>
但不确定source_name标签是否正确,且无法区分普通进程和服务进程,于是尝试以下Bash脚本:
对比脚本comp.sh:
#!/bin/bash file1="$2" file2="$1" while IFS= read -r line; do grep -q "$line" "$file2" || echo "New process ID was found: $line" done < "$file1"
主监控脚本:
#!/bin/bash while true; do # Create new f1.txt file ps -e | awk '{print $1, $4}' > f1.txt # Compare f1.txt with last f2.txt file if [ -f f2.txt ]; then sh comp.sh f1.txt f2.txt >> result.txt fi # Rename f1.txt to f2.txt mv f1.txt f2.txt # Sleep for 1 second sleep 1 done
但使用时脚本会检测到自身启动的进程,不知如何解决。
解决方案
一、Wazuh原生方案(推荐)
完全可以通过Wazuh的规则和集成能力实现需求,无需额外脚本。
1. 配置Wazuh Agent的进程监控
在Wazuh Agent的ossec.conf中添加进程监控配置,指定要排除的服务进程:
<wodle name="command"> <disabled>no</disabled> <tag>process_monitor</tag> <command>ps -eo pid,cmd --no-header | grep -vE "(systemd|docker|nginx|apache|sshd)"</command> <!-- 按需添加要排除的服务关键字 --> <interval>10</interval> <ignore_output>no</ignore_output> <run_on_start>yes</run_on_start> </wodle>
grep -vE后的正则可根据实际环境调整,覆盖所有服务类进程名。interval设置为10秒(可按需修改监控频率)。
2. 编写Wazuh检测规则
在local_rules.xml中添加规则,对比进程列表差异触发告警:
<group name="process_monitor,"> <rule id="100001" level="7"> <if_sid>500</if_sid> <match>^ossec: output: 'process_monitor:'</match> <list field="full_log" lookup="changed">etc/lists/process_list.txt</list> <description>New non-service process detected: $(full_log)</description> <options>no_full_log</options> </rule> </group>
- Wazuh会自动维护
process_list.txt,对比每次命令输出的差异,发现新进程时触发告警。 - 告警级别
level可根据需求调整(1-15)。
3. 验证配置
重启Wazuh Agent生效:
systemctl restart wazuh-agent
启动一个普通进程(如vim test.txt),检查Wazuh Manager的告警面板即可看到对应告警。
二、修复Bash脚本方案
如果坚持使用脚本,需排除脚本自身及相关进程:
1. 修改主监控脚本
在ps命令中过滤掉脚本自身PID和相关进程名:
#!/bin/bash # 获取当前脚本的PID SCRIPT_PID=$$ while true; do # 过滤脚本自身、comp.sh、bash、ps、awk等相关进程 ps -e | awk -v script_pid="$SCRIPT_PID" '{if ($1 != script_pid && $4 !~ /comp.sh|bash|ps|awk/) print $1, $4}' > f1.txt if [ -f f2.txt ]; then sh comp.sh f1.txt f2.txt >> result.txt fi mv f1.txt f2.txt sleep 1 done
2. 优化对比脚本(可选)
用comm命令替代原对比逻辑,提升效率:
#!/bin/bash file1="$2" file2="$1" # 对比两个文件,只显示file1独有的新进程 comm -13 <(sort "$file2") <(sort "$file1") | while read -r line; do echo "New process ID was found: $line" done
内容的提问来源于stack exchange,提问作者Oumaima Berjane
相关产品推荐
相关产品推荐

