Daniel, Thanks for the reply. I think I might need a little clarification. I checked and I have no files listed as "register_rule" in my install directory:
r...@mserver # pwd /dir1/dir2/dir3/ossec-hids-2.4/src/analysisd r...@myserver # ls -la total 1176 drwxr-xr-x 5 nobody nobody 2048 Apr 7 10:58 . drwxr-xr-x 29 nobody nobody 2048 Apr 7 10:58 .. -rwxr-xr-x 1 nobody nobody 1455 Mar 4 15:12 active-response.c -rwxr-xr-x 1 nobody nobody 856 Mar 4 15:12 active-response.h drwxr-xr-x 2 nobody nobody 1024 Apr 7 10:58 alerts -rwxr-xr-x 1 nobody nobody 37630 Apr 6 16:58 analysisd.c -rwxr-xr-x 1 nobody nobody 752 Mar 4 15:12 analysisd.h -rwxr-xr-x 1 nobody nobody 15204 Mar 4 15:12 cleanevent.c drwxr-xr-x 2 nobody nobody 1024 Apr 7 10:58 compiled_rules -rwxr-xr-x 1 nobody nobody 1712 Mar 4 15:12 config.c -rwxr-xr-x 1 nobody nobody 545 Mar 4 15:12 config.h drwxr-xr-x 3 nobody nobody 1024 Apr 7 10:58 decoders -rwxr-xr-x 1 nobody nobody 4846 Mar 10 10:17 dodiff.c -rwxr-xr-x 1 nobody nobody 15852 Mar 4 15:12 eventinfo.c -rwxr-xr-x 1 nobody nobody 4216 Mar 4 15:12 eventinfo.h -rwxr-xr-x 1 nobody nobody 2869 Apr 6 16:58 eventinfo_list.c -rwxr-xr-x 1 nobody nobody 8366 Apr 1 11:10 fts.c -rwxr-xr-x 1 nobody nobody 587 Mar 4 15:12 fts.h -rwxr-xr-x 1 nobody nobody 998 Mar 9 11:29 Makefile -rwxr-xr-x 1 nobody nobody 782622 Apr 7 10:58 ossec-analysisd -rw-r--r-- 1 nobody nobody 1964 Mar 4 15:12 picviz.c -rw-r--r-- 1 nobody nobody 575 Mar 4 15:12 picviz.h -rw-r--r-- 1 nobody nobody 24809 Mar 4 15:12 prelude.c -rw-r--r-- 1 nobody nobody 723 Mar 4 15:12 prelude.h -rwxr-xr-x 1 nobody nobody 67905 Mar 9 11:29 rules.c -rwxr-xr-x 1 nobody nobody 5413 Mar 9 11:29 rules.h -rwxr-xr-x 1 nobody nobody 13363 Mar 4 15:12 rules_list.c -rwxr-xr-x 1 nobody nobody 12673 Mar 4 15:12 stats.c -rwxr-xr-x 1 nobody nobody 158 Jun 3 2006 stats.h -rwxr-xr-x 1 nobody nobody 13905 Mar 10 16:08 testrule.c r...@myserver # also, when you ask about distribution, do you mean the OS on the server? I'm pretty sure it's Oracle Enterprise Linux, the server was built by someone else. r...@myserver # uname -a Linux myserver 2.6.18-164.6.1.0.1.el5 #1 SMP Tue Nov 3 19:09:14 EST 2009 x86_64 x86_64 x86_64 GNU/Linux Perhaps I need to run the tar/unzip process again since the files are missing? thanks, anne
