You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用Wazuh或脚本实现Linux进程启动告警(排除自身进程)

Linux普通进程启动告警(基于Wazuh+脚本优化方案)

问题描述

我需要监控Linux进程,目前正在使用Wazuh,希望实现普通进程启动时的告警(排除服务进程),请问是否可行?

最初尝试编写Wazuh规则检测程序启动:

<local_rules>
  <group name="syslog,">
    <rule id="9999" level="10">
      <program_name>.*</program_name>
      <source_name>syslog</source_name>
      <option name="description" value="Process monitoring rule." />
    </rule>
  </group>
</local_rules>

但不确定source_name标签是否正确,且无法区分普通进程和服务进程,于是尝试以下Bash脚本:

对比脚本comp.sh:

#!/bin/bash

file1="$2"
file2="$1"

while IFS= read -r line; do

    grep -q "$line" "$file2" || echo "New process ID was found: $line" 

done < "$file1" 

主监控脚本:

#!/bin/bash

while true; do
    # Create new f1.txt file
    ps -e | awk '{print $1, $4}' > f1.txt
    
    # Compare f1.txt with last f2.txt file
    if [ -f f2.txt ]; then
        sh comp.sh f1.txt f2.txt >> result.txt
    fi
    
    # Rename f1.txt to f2.txt
    mv f1.txt f2.txt
    
    # Sleep for 1 second
    sleep 1
done

但使用时脚本会检测到自身启动的进程,不知如何解决。


解决方案

一、Wazuh原生方案(推荐)

完全可以通过Wazuh的规则和集成能力实现需求,无需额外脚本。

1. 配置Wazuh Agent的进程监控

在Wazuh Agent的ossec.conf中添加进程监控配置,指定要排除的服务进程:

<wodle name="command">
  <disabled>no</disabled>
  <tag>process_monitor</tag>
  <command>ps -eo pid,cmd --no-header | grep -vE "(systemd|docker|nginx|apache|sshd)"</command> <!-- 按需添加要排除的服务关键字 -->
  <interval>10</interval>
  <ignore_output>no</ignore_output>
  <run_on_start>yes</run_on_start>
</wodle>
  • grep -vE后的正则可根据实际环境调整,覆盖所有服务类进程名。
  • interval设置为10秒(可按需修改监控频率)。

2. 编写Wazuh检测规则

在local_rules.xml中添加规则,对比进程列表差异触发告警:

<group name="process_monitor,">
  <rule id="100001" level="7">
    <if_sid>500</if_sid>
    <match>^ossec: output: 'process_monitor:'</match>
    <list field="full_log" lookup="changed">etc/lists/process_list.txt</list>
    <description>New non-service process detected: $(full_log)</description>
    <options>no_full_log</options>
  </rule>
</group>
  • Wazuh会自动维护process_list.txt,对比每次命令输出的差异,发现新进程时触发告警。
  • 告警级别level可根据需求调整(1-15)。

3. 验证配置

重启Wazuh Agent生效:

systemctl restart wazuh-agent

启动一个普通进程(如vim test.txt),检查Wazuh Manager的告警面板即可看到对应告警。


二、修复Bash脚本方案

如果坚持使用脚本,需排除脚本自身及相关进程:

1. 修改主监控脚本

在ps命令中过滤掉脚本自身PID和相关进程名:

#!/bin/bash

# 获取当前脚本的PID
SCRIPT_PID=$$

while true; do
    # 过滤脚本自身、comp.sh、bash、ps、awk等相关进程
    ps -e | awk -v script_pid="$SCRIPT_PID" '{if ($1 != script_pid && $4 !~ /comp.sh|bash|ps|awk/) print $1, $4}' > f1.txt
    
    if [ -f f2.txt ]; then
        sh comp.sh f1.txt f2.txt >> result.txt
    fi
    
    mv f1.txt f2.txt
    sleep 1
done

2. 优化对比脚本(可选)

用comm命令替代原对比逻辑,提升效率:

#!/bin/bash

file1="$2"
file2="$1"

# 对比两个文件,只显示file1独有的新进程
comm -13 <(sort "$file2") <(sort "$file1") | while read -r line; do
    echo "New process ID was found: $line"
done

内容的提问来源于stack exchange,提问作者Oumaima Berjane

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.26 23:50:24