Found file log4j?

Once or every time?
Ralf

only while scanning. I added a dedicated process service to check if and how long, … the log4j-scan runs

…on Linux & Windows

Hallo,
can you post your config for this check?

It means that the CPU Load rises every time the check runs?
Any ideas how to reduced the load?
Ralf

you can check the overhead of the plugin, by running the scanner manually (with the same options as the plugin) and compare the load.

Thanks
I will check this tomorrow.
Ralf

Hi all,
Just found out yesterday, that this plugin doesn’t work on agents running on systemd. It work after I installed xinetd and changed the listening port.

I am pretty sure there is still a problem with systemd. The investigation with Tribe is still ongoing. Therefore I have temporarily switched back to xinetd.
CentOS for example has a too old systemd version (if I remember correctly).

There are some more threads about systemd and centos7.
Ralf

First of all thanks for the feddback and the :star2::star2::star2::star2::star2: on the Exchange :slight_smile:

If understand you correctly the agent ie working with systemd but not the plugin?

Sorry… I am little bit confused about agent and plugin.
What I am trying to say is; on a target host (CentOS running systemd) other checks output (CPU, memory, disk, etc.) are readable during service discovery, but there is no output from CVE-2021_44228-log4j.
When I try to restart xinetd service, I realized that port 6556 used by systemd. So I decide to change the xinetd port and re-scan the service, then CVE-2021_44228-log4j is there.

I think Doc’s reply is the answer for this :wink:

so this was not realy an issue with the CVE-2021_44228-log4j plugin, nothing to fix on my side I guess :wink:

We found out that CentOS ships a very old version of systemd. This is buggy.

Time for a change to Debian… :wink:

Hallo,
scanintervall (for excample) 86000 in the bakery is the one and only option to configure how often the scan runs?
Ralf

if you use the bakery → yes

There is a public KB article from Tribe about this.

https://kb.checkmk.com/pages/viewpage.action?pageId=17476598

Don’t start these debates here :scream:

:joy:

12345678901234567890

Hallo,
time for the next step.
The CVE scanner show me 9000 different hits in our network (177 Hosts in then moment).
Most systems are used by developers.
My question:
How did you evaluate the scan results and what are your next steps?
Ralf

  1. search for CVE services
  2. filter for “not-OK”
  3. sort in some way
  4. hand over this info to their manager
  5. run

:rofl:

Hallo,
anyone here using the exclude features?
My questions:

is it possible to define a part of a path?
c:\dir1\subdir2\subdir3\project01
should be find using \subdir2\

We have tons of directories ist a dot.
c:\dir1\subdir2.namewithdot\project01
should be found using

Is this possible and what would be the correct syntax?
Thanks
Ralf
.namewithdot