Re: [ossec-list] Re: Server Install With Db Support

2013-10-23 Thread rockandsnap
Hmm, unfortunately it didn't work. I still get this error: *** Making os_dbd *** make[1]: Entering directory `/home/theresa/ossec-hids-2.7/src/os_dbd' Compiling DB support with: gcc -g -Wall -I../ -I../headers -DDEFAULTDIR=\/var/ossec\ -DUSE_OPENSSL -DUSEINOTIFY -DARGV0=\ossec-dbd\

Re: [ossec-list] Re: Server Install With Db Support

2013-10-23 Thread rockandsnap
good news: I've fixed it myself. apparently the library mysql-devel was missing. now it installed correctly and i finally get: OSSEC HIDS v2.7 - Trend Micro Inc. Compiled with MySQL support. :) On Tuesday, March 20, 2012 11:29:05 PM UTC+1, Joshua Albright wrote: Hi, Has a fix or workaround

Re: [ossec-list] Cannot get agent profile working on windows (2nd try)

2013-10-23 Thread Chris H
On Friday, September 27, 2013 3:39:38 PM UTC+1, Chris H wrote: On Thursday, September 26, 2013 5:25:10 PM UTC+1, Chris H wrote: On Thursday, September 26, 2013 3:49:39 PM UTC+1, dan (ddpbsd) wrote: On Thu, Sep 26, 2013 at 10:29 AM, Chris H chris@gmail.com wrote: On

[ossec-list] Re: How to bypass default msauth_rules?

2013-10-23 Thread tww0101
Hi Dan, I did notice that the windows event log was a mess so that the default decoder and msauth rule retrieved the following values during phase 2: **Phase 2: Completed decoding. decoder: 'windows' status: 'AUDIT_SUCCESS' id: '4740' extra_data: 'XX'

[ossec-list] OSSEC in the Enterprise?

2013-10-23 Thread InfoSec Guy
Hello, We are looking to test this in our enterprise environment. Are there any examples or any references to this being used on point of sale devices within large size companies? -- --- You received this message because you are subscribed to the Google Groups ossec-list group. To

Re: [ossec-list] VNC Windows Server Alerts

2013-10-23 Thread dan (ddp)
On Wed, Oct 23, 2013 at 2:00 PM, Forums for...@cyberwatchers.com wrote: You should know, all is documented in the email. You’re the one that had me I will look for clearly labeled RDP log messages so I can test this and try to get it working for you. add in the decoder rule. You’re the OSSEC

Re: [ossec-list] VNC Windows Server Alerts

2013-10-23 Thread dan (ddp)
On Wed, Oct 23, 2013 at 2:50 PM, dan (ddp) ddp...@gmail.com wrote: On Wed, Oct 23, 2013 at 2:00 PM, Forums for...@cyberwatchers.com wrote: You should know, all is documented in the email. You’re the one that had me I will look for clearly labeled RDP log messages so I can test this and try

Re: [ossec-list] VNC Windows Server Alerts

2013-10-23 Thread dan (ddp)
On Wed, Oct 23, 2013 at 2:56 PM, dan (ddp) ddp...@gmail.com wrote: On Wed, Oct 23, 2013 at 2:50 PM, dan (ddp) ddp...@gmail.com wrote: On Wed, Oct 23, 2013 at 2:00 PM, Forums for...@cyberwatchers.com wrote: You should know, all is documented in the email. You’re the one that had me I will

RE: [ossec-list] VNC Windows Server Alerts

2013-10-23 Thread Forums
Sorry for my earlier comments I understand you are busy sorry people treat you like I just did. Anyway, My fault, I thought I had RDP logs in this posting but it was the one I resolved earlier a few weeks ago. I can research and figure it out later but thanks for all the help earlier much

[ossec-list] checksum

2013-10-23 Thread David Juarez
Hello, Where can I find documentation to restrict user's to be notified for checksum (changing files, directories)? If would like to be notified for any changes on files and directories for other people than me.. Many Thanks. Regards, David J. -- --- You received this message because you

Re: [ossec-list] checksum

2013-10-23 Thread Saul Alanis
How about a distribution list? On Oct 23, 2013 7:49 PM, David Juarez djuar...@usfca.edu wrote: Hello, Where can I find documentation to restrict user's to be notified for checksum (changing files, directories)? If would like to be notified for any changes on files and directories for other