HP-UX Host Intrusion Detection System Version 4.3 administrator guide

Table Of Contents
The OVO HPUX_HIDS-SPI has been certified by HP for OVO V5.x as well as V6.x, and is known
to work with OVO V7.1. A future HPUX_HIDS-SPI release is being planned for certification with
OVO V8.
HP Reference
For more information, see HP OpenView Operations SMART Plug-In for HP-UX Host IDS
Administrators and Users Guide available at:
http://www.managementsoftware.hp.com/products/spi/spi_ids/spi_ids_guide_22.pdf
OVO Enablement in HP-UX HIDS
OVO integration is enabled with two programs that are installed on every agent host defined
by the IDS_RESPONSE_DIR configuration variable. By default, they are:
/opt/ids/response/send_alert_to_vpo.sh /opt/ids/response/vpo/ids_vpoalert
The script send_alert_to_vpo.sh performs a series of tests to ensure that the script is running
on a OVO managed node. If the tests pass, it calls ids_vpoalert, which generates a OVO
message and uses the opcmsg() facility to send the message to the OVO message interceptor.
The interceptor relays the message to the OVO management server.
If you do not have OVO or prefer not to have OVO integrated with HP-UX HIDS, then you can
remove these two files from the /opt/ids/response directory.
178 Automated Response for Alerts