I forgot to mention, if the machine is configured to get it's address from a
DHCP server, then it's OK to ignore the alert.

-----Original Message-----
From: Jeremy Melanson 
Sent: Thursday, October 12, 2006 9:39 PM
To: '[email protected]'; '[EMAIL PROTECTED]'
Subject: RE: [ossec-list] Ossec and nagios?

If it's not tcpdump or some other libpcap application... Is the machine
configured for DHCP?

-----
Jeremy

-----Original Message-----
From: Dennis Borkhus-Veto [mailto:[EMAIL PROTECTED] 
Sent: Thursday, October 12, 2006 7:13 PM
To: [EMAIL PROTECTED]
Subject: [ossec-list] Ossec and nagios?

I have been working on setting up a program called nagios on the same server
as ossec and now I recdieved the folllowing error and am not sure if it is
related.

OSSEC HIDS Notification.
2006 Oct 12 11:58:27

Received From: HULK->/Raid/Log/messages
Rule: 5104 fired (level 8) -> "Interface entered in promiscuous(sniffing)
mode."
Portion of the log(s):

kernel: device eth0 entered promiscuous mode


Dennis

______________________________________________________________________
This email has been scanned by the MessageLabs Email Security System.
For more information please visit http://www.messagelabs.com/email 
______________________________________________________________________

Reply via email to