[ossec-list] Re: Composite Rule Help

2010-05-10 Thread Dave S
So Phil, I checked out your posting. What did you fix to make it work? And Eric, same_source_ip / is a legit tag for a composite rule. See http://www.ossec.net/main/manual/configuration-options/#rules_options Table 4.1 - Dave

RE: [ossec-list] Re: SYSLOG-NG AND OSSEC FOR LOG ANALYSING

2010-05-10 Thread Muraleedaran Kanapathy
Hi Dave Sorry for the late reply as I was out of Office I followed the steps, but still I am not receiving the logs , including from CISCO router as well Also can I search these logs via the web interface, or can I create any queries Kindly help Muraleedaran Kanapathy| Linux/Unix System

[ossec-list] Re: Active response working on agents but not on server

2010-05-10 Thread tm
Dan, Upon reading the OSSEC book again it appears to confirm my suspicion that all means all agents. So, how do you include the server as well? I tried locationserver,all/location as someone else's post suggested but it doesn't work. The active response seems to work only on the server if I

Re: [ossec-list] Re: SU rules issue with Linux and OSSEC 2.4.1

2010-05-10 Thread dan (ddp)
Running two of the logs through ossec-logtest shows a few differences: May 7 09:50:46 Server su(pam_unix)[17639]: authentication failure; logname=username uid=500 euid=0 tty=pts/0 ruser=username rhost= user=root **Phase 1: Completed pre-decoding. full event: 'May 7 09:50:46 Server

[ossec-list] ossec for log analysis

2010-05-10 Thread Muraleedaran Kanapathy
Dear Sirs We are in the process of installing the OSSEC for the log analyzing purposes for the PCI DSS requirement In windows I have installed the OSSEC agent, but I am unable to see any Windows event logs such Application, System, except for the Security logs ( Including CISCO logs)

RE: [ossec-list] Re: SYSLOG-NG AND OSSEC FOR LOG ANALYSING

2010-05-10 Thread Muraleedaran Kanapathy
Hi Dave Sorry for the late reply as I was out of Office I followed the steps, but still I am not receiving the logs , including from CISCO router as well Also can I search these logs via the web interface, or can I create any queries Kindly help Muraleedaran Kanapathy| Linux/Unix System

Re: [ossec-list] ossec for log analysis

2010-05-10 Thread Daniel Cid
Hi, OSSEC by default will only generate alerts on events that have potential security value. Most events from the System and Application event log are just informational and OSSEC will not store them. If you need to have all of them stored, go to your ossec.conf (on the manager) and set logall

[ossec-list] RE: ossec for log analysis

2010-05-10 Thread Max Williams
Hi Muraleedaran, You cannot browse all windows events from the web interface, you can only view Windows Events that have been triggered by a rule to generate an alert. Take a look in this file on the ossec server: osse_path/rules/msauth_rules.xml You could write your own rule to generate alerts

Re: [ossec-list] Re: Comprehensive manual - or - something

2010-05-10 Thread Alessandro Di Giuseppe
Sounds reasonable, but if accounts are indeed manually created, how is spam getting into the wiki then? From: Chris Buechler cbuech...@gmail.com To: ossec-list@googlegroups.com Sent: Fri, May 7, 2010 7:39:41 PM Subject: Re: [ossec-list] Re: Comprehensive manual

[ossec-list] ANALIZE WINDOWS CHECKPOINT LOGS

2010-05-10 Thread Jorge cruces
Hello, I have 3 checkpoint firewalls in windows. Is there any way to send the logs to ossec? Juan Jorge Cruces Fernández Accelya

RE: [ossec-list] RE: ossec for log analysis

2010-05-10 Thread Muraleedaran Kanapathy
Hi Max Thanks a lot for the reply May I know what did you use to collect the logs from network devices? (Router and switches) And OSSEC did you use it only for File Integrity check, if so what is the syslog and syslog viewer you implemented Kindly advice Muraleedaran

Re: [ossec-list] Re: SU rules issue with Linux and OSSEC 2.4.1

2010-05-10 Thread Nicholas Ritter
The two different sets of log entry samples came from two different versions of Linux. The remote servers are using spitting out the first log entries when the remote servers are RHEL v4 based (I have not tested RHEL v5.) The local ossec management server, that all the agents talk to, is running

Re: [ossec-list] ossec for log analysis

2010-05-10 Thread dan (ddp)
The logall option will save the logs in /var/ossec/logs/archives/ (after restarting the server of course). There probably aren't any default rules for these logs, so you may have to write your own. You should be able to forward the syslog data to a system that is listening for syslog messages so

Re: [ossec-list] Re: SU rules issue with Linux and OSSEC 2.4.1

2010-05-10 Thread dan (ddp)
The ossec regex rules are in the wiki or the manual, can't remember which. I prefer using matches where possible, regex if necessary. Ossec's pretty fast though, so regex is probably ok. On Mon, May 10, 2010 at 9:42 AM, Nicholas Ritter ritter6...@gmail.com wrote: The two different sets of log

Re: [ossec-list] Re: Comprehensive manual - or - something

2010-05-10 Thread dan (ddp)
It looks like anonymous editting was allowed for a bit. Not positive though. On Mon, May 10, 2010 at 1:34 PM, Alessandro Di Giuseppe a_di_giuse...@yahoo.com wrote: Sounds reasonable, but if accounts are indeed manually created, how is spam getting into the wiki then?