Re: [ossec-list] Agents programming language

2018-06-06 Thread Dan Avrukin
That is a really good point, didn't even occur to me to just look at the source code. Thank you. On Wed, Jun 6, 2018 at 11:51 AM dan (ddp) wrote: > On Wed, Jun 6, 2018 at 12:56 PM, Dan Avrukin > wrote: > > Thanks Dan. > > Is there a way to confirm that the agents were programmed in C? > >

Re: [ossec-list] Agents programming language

2018-06-06 Thread dan (ddp)
On Wed, Jun 6, 2018 at 12:56 PM, Dan Avrukin wrote: > Thanks Dan. > Is there a way to confirm that the agents were programmed in C? > readelf doesn't seem to be able to provide that information. > I could be thinking about the problem incorrectly, but a quick look at the source code could make

Re: [ossec-list] Agents programming language

2018-06-06 Thread Dan Avrukin
Thanks Dan. Is there a way to confirm that the agents were programmed in C? readelf doesn't seem to be able to provide that information. Thanks. On Wed, Jun 6, 2018 at 7:25 AM dan (ddp) wrote: > On Mon, Jun 4, 2018 at 4:09 PM, Void Main > wrote: > > Hello all, > > > > I've been going through

Re: [ossec-list] Re: OSSEC installation on CoreOS

2018-06-06 Thread dan (ddp)
On Wed, May 30, 2018 at 12:37 PM, wrote: > +1 on this question; really would like to know how someone did this; SDK, > toolbox, etc? > What challenges does CoreOS present that aren't a problem for a normal linux distribution? > On Thursday, November 9, 2017 at 11:37:35 AM UTC-5, SET wrote: >>

Re: [ossec-list] [v2.8.3][ossec-maild] ERROR (smtp server)

2018-06-06 Thread dan (ddp)
On Tue, May 29, 2018 at 6:07 AM, wrote: > It's empy. > > There are no entries at maillog. > > However, if I send a mail with sendmail (echo "Subject: sendmail test" | > sendmail -v x...@xxx.xxx), at /var/log/maillog: > > May 29 12:04:30 X postfix/pickup[8183]: 638F727EA4: uid=0 from= > May 29

Re: [ossec-list] FIM Syscheck

2018-06-06 Thread dan (ddp)
On Wed, Jun 6, 2018 at 6:16 AM, Mikel Sheshi wrote: > Hello, > I have Wazuh Server configured to monitor my Windows Servers > If I want to monitor a directory : Example : realtime="yes">C:\test > > When I do changes with a user logged on the server I receive all the changes > through syscheck >

Re: [ossec-list] ossec-reportd is crashing

2018-06-06 Thread dan (ddp)
On Tue, May 22, 2018 at 9:08 AM, Vibin K Madampath wrote: > Hello, > > I'm also getting a similar error due to which the reports are not being > generated/sent. > > Using the same version 2.9.3 > > [root@usws1ossecap01 ~]# /var/ossec/bin/ossec-reportd < > /var/ossec/logs/alerts/alerts.log >

Re: [ossec-list] Improving agentless sequential polling

2018-06-06 Thread dan (ddp)
On Mon, Jun 4, 2018 at 12:22 PM, Mike wrote: > Hi, > > I want to reduce the frequency of the agentless polling for quicker > performance on my manager (version 2.8) but I cannot find clues for doing > this. > > It seems to me that the agentless process runs my agentless configuration in > a

Re: [ossec-list] Agents programming language

2018-06-06 Thread dan (ddp)
On Mon, Jun 4, 2018 at 4:09 PM, Void Main wrote: > Hello all, > > I've been going through the docs, but I don't seem to find that piece of > information. > Do you happen to know what language was used to program the Agents? > Most of OSSEC is written in C. > Thanks. > > -- > > --- > You

Re: [ossec-list] [v2.8.3][ossec-maild] ERROR (smtp server)

2018-06-06 Thread Eero Volotinen
well. does telnet localhost work fine? Eero ti 29. toukok. 2018 klo 12.06 kirjoitti: > Hi, > > I am receiving the error: > > > > *2018/05/28 17:29:54 ossec-maild(1223): ERROR: Error Sending email to > 127.0.0.1 (smtp server)2018/05/28 18:00:01 ossec-maild(1223): ERROR: Error > Sending email to

[ossec-list] FIM Syscheck

2018-06-06 Thread Mikel Sheshi
Hello, I have Wazuh Server configured to monitor my Windows Servers If I want to monitor a directory : Example : C:\test When I do changes with a user logged on the server I receive all the changes through syscheck The question is: If the directory C: is shared (\\server-ip\c$) and some

Re: [ossec-list] [v2.8.3][ossec-maild] ERROR (smtp server)

2018-06-06 Thread jbalbuenawsgsec
Hi dan, I don't see anything interesing in maillog. I've enabled debug mode at postfix: Jun 6 09:39:23 XXX postfix/pickup[13143]: trigger_server_accept_fifo: trigger arrived Jun 6 09:39:23 XXX postfix/pickup[13143]: master_notify: status 0 Jun 6 09:39:23 XXX postfix/pickup[13143]: