Well, that's indeed strange then. But I can't go through the alert logs as they don't seem to be in the archive/year/month folder as I showed with the ls previously. Just the checksums appear.
Anyhow, could you (directly, to prevent spamming the list) give a sample of a daily report with command that has actual logs included it then? I've not seen actual logs be included on either server. On Aug 31, 4:22 pm, "dan (ddp)" <[email protected]> wrote: > On Tue, Aug 31, 2010 at 9:33 AM, Aeterna <[email protected]> wrote: > > Actually I'm now just running the command from cli and mailing it from > > there. So I'm getting the full report, however let me give an example: > > cat /var/ossec/logs/alerts/alerts.log | /var/ossec/bin/ossec-reportd - > > f group syscheck 2>&1 | mail -s "Syscheck report" (email address) > > > Results in the following mail: > > 2010/08/31 15:29:59 ossec-reportd: INFO: Started (pid: 13215). > > 2010/08/31 15:30:04 ossec-reportd: INFO: Report completed. Creating > > output... > > > Report completed. == > > ------------------------------------------------ > > ->Processed alerts: 1529 > > ->Post-filtering alerts: 8 > > ->First alert: 2010 Aug 31 11:13:06 > > ->Last alert: 2010 Aug 31 12:43:03 > > > Top entries for 'Level': > > ------------------------------------------------ > > Severity 7 |8 | > > > Top entries for 'Group': > > ------------------------------------------------ > > ossec |8 | > > syscheck |8 | > > > Top entries for 'Location': > > ------------------------------------------------ > > nagios->syscheck |8 | > > > Top entries for 'Rule': > > ------------------------------------------------ > > 550 - Integrity checksum changed. |5 | > > 551 - Integrity checksum changed again (2nd .. |3 | > > > However from this I can't tell what files have actually been changed, > > just that it's happened. For that I'd need to look at the actual > > (filtered) alerts. > > The question is how is the (best) way? > > That's strange, I actually get the alerts in the mail when I do it manually. > > The best way is whatever way works for you. You can dump the info into > splunk, if you're using ossec-dbd you can go through that, if you'd > rather you can just go through the alert logs, or even look at the > email messages ossec sends out about changed files.
