Actually it seems that I've been mistaken and simply looked at the
wrong directory. The log files do actually get moved to that folder
and gzipped accordingly.

Thanks for your help, I've settled for using a cron to churn out daily
reports and e-mail them. Also I've started looking at Splunk and that
looks like an interesting tool. Apologize for my stupidity at
overlooking something so elementary.

On Aug 31, 6:29 pm, "dan (ddp)" <[email protected]> wrote:
> On Tue, Aug 31, 2010 at 11:10 AM, Aeterna <[email protected]> wrote:
> > Well, that's indeed strange then.
> > But I can't go through the alert logs as they don't seem to be in the
> > archive/year/month folder as I showed with the ls  previously.
> > Just the checksums appear.
>
> > Anyhow, could you (directly, to prevent spamming the list) give a
> > sample of a daily report with command that has actual logs included it
> > then? I've not seen actual logs be included on either server.
>
> Oops, missed that in the earlier message. I'm not sure what all to
> check to track that issue down.
> I guess look in the logs to see if there is anything mentioned about
> not being able to open the
> ossec/logs/alerts/YEAR/MONTH/ossec-alert-blah.log file.
>
> Looking at the output of lsof/fstat it looks like the
> ossec/logs/alerts/alerts.log and
> ossec/logs/alerts/2010/Aug/ossec-alerts-31.log file share the same
> inode on my systems (they are essentially the same file), so I'm not
> sure why it isn't opened under both names/locations for you.
>
> I'm guessing permissions are correct, since the .sum files are being created.

Reply via email to