Hi Joachim, Can you share the logs that were created by vsftpd and proftpd on your tests? We support these two formats very well and it works on my setup. Maybe you have a difference version or format?
This is how we expect them: http://www.ossec.net/wiki/index.php/ProFTPD http://www.ossec.net/wiki/index.php/Vsftpd Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On Thu, Jul 10, 2008 at 3:13 AM, Joachim Krais <[EMAIL PROTECTED]> wrote: > > Hello group, hello Daniel, > > we use these ftp-Daemons: > * vsftp (problem with OSSEC) > * proftp (problem with OSSEC) > * pure-ftp (works fine with OSSEC) > > The distributions are SLES9SP4 and Debian. > > Ossec 1.5.1 was installed with local-settings, active-response, > firewall-functions. We establish connections to these servers in > the following ways: > * correctly (user and password exists) > * uncorrectly - simulates an attack: (user or password doesn't exist) > > We set up a tail -f to /var/ossec/log/alerts/alerts.log. > > SSH-Logins for example are correctly identified by OSSEC, but OSSEC > doesn't unfortunately show us ftp-attacks (vsftp and proftp) in the > alert.log > > Messages from pure-ftp are already correctly found by OSSEC. :-) > > Where is the problem? > > Greetings > > Joachim > > >
