EGI CSIRT:Monitoring
| Mission | Members | Contacts
| Incident handling | Alerts | Monitoring | Security challenges | Procedures | Dissemination
About EGI-CSIRT Security monitoring activities
See the description of the Security Monitoring Group for general description of the activity.
Security monitoring with Nagios
Pakiti
Pakiti is a client-server tool to collect and evaluate data about packages installed on Linux machines, primarily meant to identify vulnerable SW that have not been properly updated. The EGI CSIRT operates the EGI Pakiti instance that is used to monitor the state of the EGI sites.
A site can also choose to install its own Pakiti instance. There is a documentation guide available from the Pakiti homepage that describes the steps needed to deploy the server and clients. The Nagios probes used to launch the Pakiti client in the EGI are also available. Note, the Pakiti distribution available at the moment doesn't support all the features supported by the EGI instance of Pakiti, nevertheless it is fully working and can be used to monitor the site status.
Currently we are working on the new version of the Pakiti v3, more information is available here.
Pakiti client
If your receive pakiti-client from the EGI CSIRT team in order to run it manually on your site, follow these steps:
- Unpack received pakiti-client.tar.gz to some directory.
- Run ./Pakiti script, the script will send the report for the host where the script was executed.
- Look at the https://pakiti.egi.eu, if the host is there.
- Deploy the Pakiti client on all nodes which should be monitored (deploy all the content of the pakiti-client.tar.gz).