[ossec-list] Re: archives.log under /var/ossec/logs/

2017-07-17 Thread Kazim Koybasi
/archives directory. On Monday, 17 July 2017 09:53:37 UTC+3, Kazim Koybasi wrote: > > Is archives.log under /var/ossec/logs/ contains all logs produced at agent > host server?I am trying to understand that how OSSEC manager and agent > topology works. Agent does not contains rules.

[ossec-list] Restart agents, syscheck and rootcheck from ossec manager

2017-07-10 Thread Kazim Koybasi
Hello, I am trying to restart all agents and start syscheck and rootcheck but I can not achieve it with commands below.I use centralized agent.conf at manager and whenever I change agent.conf file I should restart all agents to take new agent.conf. I have 14 agents and restarting all one bye

[ossec-list] OSSEC log analysis settings for apache access/error.log

2017-07-06 Thread Kazim Koybasi
I added config below to etc/shared/agent.conf in ossec-server home directory but there is no alerts in server.What could I need with this configuration? apache /var/log/httpd/site/site_log -- --- You received this message because you are subscribed to the Google

[ossec-list] Re: OSSEC log analysis settings for apache access/error.log

2017-07-06 Thread Kazim Koybasi
7 vhost so there is so much log. Can the reason of that from type of apache server log format? For example my apache has some server combined log format and some other common log format. /var/log/httpd/*/*_log On Thursday, 6 July 2017 23:37:55 UTC+3, Kazim Koybasi wrote: > > I added

[ossec-list] Re: OSSEC log analysis settings for apache access/error.log

2017-07-09 Thread Kazim Koybasi
Thank you for your answers.Now It triggers that rule 31152 normally.I was overwrited the rule frequency in local rules and forgot that.Sorry for that mistake. On Thursday, 6 July 2017 23:37:55 UTC+3, Kazim Koybasi wrote: > > I added config below to etc/shared/agent.conf in ossec-serve

[ossec-list] archives.log under /var/ossec/logs/

2017-07-17 Thread Kazim Koybasi
Is archives.log under /var/ossec/logs/ contains all logs produced at agent host server?I am trying to understand that how OSSEC manager and agent topology works. Agent does not contains rules. Is it mean that agent send all logs to manager and it process log files according to decoder and rule

[ossec-list] Re: OSSEC log analysis settings for apache access/error.log

2017-07-07 Thread Kazim Koybasi
Yes OSSEC mentioning about log files and says analyzing log file. I tried with apache log format and without logformat settings and results is same.What could be a workaround for that? On Thursday, 6 July 2017 23:37:55 UTC+3, Kazim Koybasi wrote: > > I added config below to etc/

[ossec-list] Grouping syscheck email alerts per agent.

2017-06-20 Thread Kazim Koybasi
Is it possible to group syscheck email alert per agent? -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to ossec-list+unsubscr...@googlegroups.com. For more

[ossec-list] Re: How to start syscheck at same time in a weekdays?

2017-06-19 Thread Kazim Koybasi
Hi, Thanks for your answer.I edited manager ossec.conf and add same config in it. Agents syscheck worked in 24 hours after create first database.But manager not run shscheck after 24 hours of database initialization. Does configuration in manager ossec.conf affects agents? Thanks for reading.

[ossec-list] Re: Grouping syscheck email alerts per agent.

2017-06-21 Thread Kazim Koybasi
Thanks for your answer. It helped. -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to ossec-list+unsubscr...@googlegroups.com. For more options, visit

[ossec-list] Re: How to start syscheck at same time in a weekdays?

2017-06-19 Thread Kazim Koybasi
Hi, Thank you for your answers. Is it possible to group all alerts for agent in one alert mail? -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to

[ossec-list] How to start syscheck at same time in a weekdays?

2017-06-17 Thread Kazim Koybasi
I want to manually trigger Wazuh OSSEC syscheck like AIDE. I configure it to check manually every day at 08:00 with below shared/agent.conf but even whan I start syscheck with agent_control -r -a .It does not report changes to alets.log. Do manager ossec.conf affect agents or every agent