Found file log4j?

another one

“Files itigated” or “mitigated”?

Files potential vulnerable: 0
Files itigated: 0
Files scanned: 52485

Are you planning to add man page entries?

And I’m not sure about copyright. It might make sense to add something about logpresso.
I’m completely unsure about that. That’s why I had added the help on how to download it myself.

I guess I wait till you found all the typos :slight_smile:

I think that’s it so far.

Increase the version number so that “Extension packages” will find the update.

Let’s have a beer together at the next conference! :beers:

done. Let’s hope ther will be a real conference next year :beers:. About the license, there is a link to the repository, I thik this is ok.

Not really. I am not a big fan of this kind of documentation. But if you (or some one else) like to write one, I am happy to add it to the package.

1 Like

@all

First tests look very good. I would be helpful if more of you can test @thl-cmk 's plugin.

Post the results here please. Thank you!

:partying_face:

1 Like

@thl-cmk, @martin.hirschvogel and all others

The logpresso scan tool was ported to arm, MacOS (also for M1), linux-aarch

Is someone able to test this? I have to eat cake today.

Let’s make our lovley Monitoring Tool checkmk the vaccine for log4j!
If someone knows where @martin.hirschvogel can start advertisements to reach the important persons. Help him!

1 Like

for your own safty use antivirus tools before using the binaries
i.e. https://www.virustotal.com/gui/home/upload

I successfully tested the Darwin binary on a M1 Mac.

so I…
…removed the old mkp and installed the new one
…copied the ps1 to the plugins folder and the exe to the bin folder
…added the lines for the plugin into the check_mk.user.yml
…enabled the cve service check as enforced for all my windows machines.

but the service check on the machine is (Pend) stale?

Good morning,

Pleas use this one here @thl-cmk ported the Local Check into a Plugin. I tested this yesterday. Looks very good.

I already do, i discovered it this morning

mh I configured it as enforced service. i deleted this and configured it like in the gitlab description.
but then the service no longer shows up at the host in checkmk?

Same for me. With enforced service it’s ‘stale’ and otherwise, the service doesn’t show up.
This is supposed to work for existing hosts where the agent is already installed, right ?

Because it’s an local check/agent plugin you need an agent to call the script and transfer the results back to your monitoring server

So I installed the extension package and configured it in wato as it says in the gitlab instructions. I have to do more than that?

So you are using the agent bakery? Have you created the new agent files and distributed it to the hosts?

have you deploed the agent via the bakery (automatic agent update)? If not you need to do so, or redeploy the agent with your software management system. At the moment I m writing al little section on how to use the plugin, maybe this will help (it’s work in progress so be patient)

2 Likes

So it wont work while following the manual steps?

There is nothing to enforce here

see my last post, the documentaion is work in progress, best to try it for one host with the guiedlines from the new “how to” secttion. Please note the file names in the manual have already changed for future improvement.

got that. like i said, i deleted the enforced service in checkmk, but then the service is not found for the folder I applied the new service rule.