Hey Daniel,
When I use the Mysql in OSSEC, I met some questions about it:
1. OSSEC run very well under the default decoder and rules, except the "agent"
Table.
I guess the "agent" table should be insert some records like the "server"
table,
but there is nothing in the "agent" table. Why?
2. I defined some decoder and rules like "SSHD", and disabled the default
decoder and rules of "SSHD".
When "id" > 65000, in database, the "alert" table could not insert record,
but the "data" table could,
I check the "Alert" log file,the log is OK.
When "id" < 65000, the "alert" table and the "data" table all have records.
Please tell me why!
I'll cut some pictures of the Mysql and attach the decoder, ossec.conf,
test_rules, ossec.log and alert log to you.
My English is limited, hope you can understand.
Thanks,
Guan yue