Re: [ossec-list] RE: Centos upgrade vs Ubuntu

2014-09-12 Thread Morgan Cox
Last time I had to use a Ubuntu, it was calling canonical every 30 minutes. Yes it was checking if you have updates.. On 12 September 2014 15:02, Binet, Valere (NIH/NIA/IRP) [C] bin...@nia.nih.gov wrote: Last time I had to use a Ubuntu, it was calling canonical every 30 minutes. I

[ossec-list] Re: Issue triggering Active Response on Windows 2012

2014-08-05 Thread morgan cox
Just to add i'm having the same issue on Windows 2008/2012 servers with AR and Ossec 2.8 https://groups.google.com/forum/#!topic/ossec-list/bTAbuvSZKGo -- --- You received this message because you are subscribed to the Google Groups ossec-list group. To unsubscribe from this group and stop

Re: [ossec-list] 2.8 - Active response on Windows agents not working ?

2014-07-29 Thread morgan cox
Hi Still not got anywhere with this. On the agent I have active-response disabledno/disabled /active-response On the server I have command namewin_nullroute/name executableroute-null.cmd/executable expectsrcip/expect timeout_allowedyes/timeout_allowed /command

Re: [ossec-list] Prep for next release. (2.8.1)

2014-07-23 Thread Morgan Cox
Hi Are these going to be official / semi official packages ? I ask as i'm beginning to deploy ossec now but will hold if if packages are going to be produced. regards On 9 July 2014 19:35, Santiago Bassett santiago.bass...@gmail.com wrote: Sure! For debian packages you will need the debian

Re: [ossec-list] 2.8 - Active response on Windows agents not working ?

2014-07-08 Thread morgan cox
:] *On Behalf Of *Morgan Cox *Sent:* Wednesday, July 02, 2014 11:23 AM *To:* ossec...@googlegroups.com javascript: *Subject:* [ossec-list] 2.8 - Active response on Windows agents not working ? Hi I cannot get active response to work how can I debug why active response on Windows agents

[ossec-list] 2.8 - Active response on Windows agents not working ?

2014-07-02 Thread Morgan Cox
Hi I cannot get active response to work how can I debug why active response on Windows agents is not working ? linux agents are fine - i.e drop/active response is working I have followed - http://ossec-docs.readthedocs.org/en/latest/manual/ar/ar-windows.html when I use the command : -

Re: [ossec-list] Level 7 alerts - no email ?

2013-12-02 Thread Morgan Cox
Hi Are you hitting the max emails per hour limit (10 I think)? Yes I will be - how do I increase this ? Or better still remove the limit ? Regards On 2 December 2013 14:16, dan (ddp) ddp...@gmail.com wrote: On Wed, Nov 27, 2013 at 1:02 PM, morgan cox morganco...@gmail.com wrote: Hi

Re: [ossec-list] Level 7 alerts - no email ?

2013-12-02 Thread Morgan Cox
Thanks for that Dan Cheers On 2 December 2013 14:53, dan (ddp) ddp...@gmail.com wrote: On Mon, Dec 2, 2013 at 9:41 AM, Morgan Cox morganco...@gmail.com wrote: Hi Are you hitting the max emails per hour limit (10 I think)? Yes I will be - how do I increase this ? Or better still

[ossec-list] Ossec 2.7 agent installer broken on Ubuntu 10.04

2012-11-22 Thread morgan cox
just tried to install ossec 2.7 Server install seems fine. however the 2.7 agent setup on Ubuntu 10.04 doesn't install correctly. I have tested on 2 different ubuntu machines and get the same issue. For a start during the install - after the '3- Configuring the OSSEC HIDS.' msg I see

[ossec-list] Ossec 2.7 agent broken on Ubuntu 10.04

2012-11-22 Thread Morgan Cox
Hi. hi - just tried to install ossec 2.7 Server install seems fine. however the 2.7 agent setup on Ubuntu 10.04 doesn't install correctly. I have tested on 2 different ubuntu machines and get the same issue. For a start during the install - after the '3- Configuring the OSSEC HIDS.' msg I see

Re: [ossec-list] Re: Want to see name of user who changed a file

2012-11-20 Thread Morgan Cox
Perhaps you should migrate to Linux?

Re: [ossec-list] ossec-reportd - log file dumps?

2011-03-11 Thread Morgan Cox
ignore my last comment... Sent to wrong person On 11 March 2011 16:57, Morgan Cox morganco...@gmail.com wrote: They should be usiing the ossec agent ... This isn't our ossec server is it ? (i assume not as its not running) regards On 11 March 2011 16:31, Kat uncommon...@gmail.com wrote

Re: [ossec-list] ossec-reportd - log file dumps?

2011-03-11 Thread Morgan Cox
They should be usiing the ossec agent ... This isn't our ossec server is it ? (i assume not as its not running) regards On 11 March 2011 16:31, Kat uncommon...@gmail.com wrote: I saw a few comments about this but never an answer... When I run my daily reports - if it is run from inside of