I forgot to mention, if the machine is configured to get it's address from a DHCP server, then it's OK to ignore the alert.
-----Original Message----- From: Jeremy Melanson Sent: Thursday, October 12, 2006 9:39 PM To: '[email protected]'; '[EMAIL PROTECTED]' Subject: RE: [ossec-list] Ossec and nagios? If it's not tcpdump or some other libpcap application... Is the machine configured for DHCP? ----- Jeremy -----Original Message----- From: Dennis Borkhus-Veto [mailto:[EMAIL PROTECTED] Sent: Thursday, October 12, 2006 7:13 PM To: [EMAIL PROTECTED] Subject: [ossec-list] Ossec and nagios? I have been working on setting up a program called nagios on the same server as ossec and now I recdieved the folllowing error and am not sure if it is related. OSSEC HIDS Notification. 2006 Oct 12 11:58:27 Received From: HULK->/Raid/Log/messages Rule: 5104 fired (level 8) -> "Interface entered in promiscuous(sniffing) mode." Portion of the log(s): kernel: device eth0 entered promiscuous mode Dennis ______________________________________________________________________ This email has been scanned by the MessageLabs Email Security System. For more information please visit http://www.messagelabs.com/email ______________________________________________________________________
