[ossec-list] No server respone

2013-10-15 Thread Eli
I have installed ossec server on linux mint client on win7. After adding client and extracting key I started the windows client. The client is now transmitting tto udp port 1514, however for some reason the server is not replying. The network connection is OK and pinging between machines works

Re: [ossec-list] Client.keys

2013-10-15 Thread koby yakov
Hi Chris, i'm facing with the same issue that you were having here, my current status is: i'm abling to install the agents on the windows machine, copy the conf file and create the agents on the server side. i need your assistence with extracting the keys from the server side and insert

Re: [ossec-list] No server respone

2013-10-15 Thread Pranav Lal
Hi Eli, What do the logs on the agent and those on the server show? Pranav On 10/15/13, Eli senditheredu...@gmail.com wrote: I have installed ossec server on linux mint client on win7. After adding client and extracting key I started the windows client. The client is now transmitting tto

Re: [ossec-list] No server respone

2013-10-15 Thread Eli
ossec.log says: ERROR: Incorrectly formatted message from '4.4.4.3' (my agent ip) Guess I should have looked here earlier. How do I fix this? Thanks On Tuesday, 15 October 2013 13:27:02 UTC+3, Pranav Lal wrote: Hi Eli, What do the logs on the agent and those on the server show? Pranav

Re: [ossec-list] No server respone

2013-10-15 Thread Pranav Lal
Hi, There is an error in the key that you are entering into the agent. I had this happen to me the first time I ran ossec (2 weeks ago). Look for characters like hard returns. I was lucky, that I spotted them correctly. Pranav On 10/15/13, Eli senditheredu...@gmail.com wrote: ossec.log says:

Re: [ossec-list] No server respone

2013-10-15 Thread Eli
Thanks. That did the trick. What about the Unable to start OSSEC (check config) error? How do I get rid of that? On Tuesday, 15 October 2013 16:02:14 UTC+3, Pranav Lal wrote: Hi, There is an error in the key that you are entering into the agent. I had this happen to me the first time I

[ossec-list] missing something

2013-10-15 Thread Rhoads, Robert W.
Hello, I am running OSSEC 2.7 and have been doing so successfully for a while now, but overnight something happened and I'm missing something to fix it. I am no longer getting email for events from the OSSEC server. Nothing has changed on the Windows agents or the Ossec server. I have

Re: [ossec-list] missing something

2013-10-15 Thread dan (ddp)
On Tue, Oct 15, 2013 at 9:43 AM, Rhoads, Robert W. rhoa...@ci.danville.va.us wrote: Hello, I am running OSSEC 2.7 and have been doing so successfully for a while now, but overnight something happened and I’m missing something to “fix” it. I am no longer getting email for events from

[ossec-list] Re: Empty Src Location: in alert using GeoIP while srcip is found

2013-10-15 Thread Bernard
Yes I did, except for the compiling. The compiled version of OSSEC from the repository came with maild.geoip=1 by default. I configured ossec.conf the way you showed below and ossec.log does not complain about the added XML-tags. So I assume OSSEC understands the tags and it does show the 'Src

[ossec-list] Ossec Syscheck don't check integrity

2013-10-15 Thread Cristiano Galdino
Hi! I installed the default OSSEC SERVER 2.7.1-beta-1 on Debian 7. This is my */var/ossec/etc/ossec.conf*: [...] syscheck !-- Frequency that syscheck is executed - default to every 22 hours - 79200 -- frequency*300*/frequency alert_new_filesyes/alert_new_files !-- Directories

Re: [ossec-list] Ossec Syscheck don't check integrity

2013-10-15 Thread dan (ddp)
On Tue, Oct 15, 2013 at 2:10 PM, Cristiano Galdino cristiano.gald...@gmail.com wrote: Hi! I installed the default OSSEC SERVER 2.7.1-beta-1 on Debian 7. This is my /var/ossec/etc/ossec.conf: [...] syscheck !-- Frequency that syscheck is executed - default to every 22 hours - 79200 --

RE: [ossec-list] No server respone

2013-10-15 Thread Pranav Lal
Hi, snip What about the Unable to start OSSEC (check config) error? PL] I don't know. Pranav -- --- You received this message because you are subscribed to the Google Groups ossec-list group. To unsubscribe from this group and stop receiving emails from it, send an email to

[ossec-list] Display src_ip as hostname

2013-10-15 Thread Jeff Allison
Is there anyway to display the src_ip field as a hostname in the reports generated by ossec-reportd. -- --- You received this message because you are subscribed to the Google Groups ossec-list group. To unsubscribe from this group and stop receiving emails from it, send an email to