Hi all, I have recently upgraded a firewall I manage from CentOS 4.x to Ubuntu 10.04 based system, I have installed the latest from repos Shorewall and the latest Ossec 2.5.1.
Under the old system drops and redirects were logged and Ossec would report them to me via email. Now this does not happen. I can see the Shorewall entries in the /var/log/messages file as expected but Ossec will not report them to me. I now have 2 servers that do the same thing. I have attached entries from one firewall that is working and one that does not. This one is working: Oct 27 10:07:20 gateway kernel: Shorewall:loc2all:ACCEPT:IN=eth1 OUT=XXX SRC=XXX.XXX.XXX.XXX DST=XXX.XXX.XXX.XXX LEN=78 TOS=0x00 PREC=0x00 TTL=63 ID=22537 PROTO=UDP SPT=XXX DPT=XXX LEN=58 This in CentOS 4.X with Ossec 2.4.1 This one is not: Oct 27 10:08:12 localhost kernel: [139017.036739] Shorewall:loc2fw:ACCEPT:IN=eth1 OUT= MAC=---------------------------------------- SRC=xxx.xxx.xxx.xxx DST=xxx.xxx.xxx.xxx LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=29371 DF PROTO=TCP SPT=40876 DPT=3128 WINDOW=5840 RES=0x00 SYN URGP=0 This one is on Ubuntu 10.04 with Ossec 2.5.1 Could the [139017.036739] in the second entries be the issue and the decoder regx is getting confused? I though that Ossec looked for the program in the 3 field? Sorry if that is way off base? Thanks for any help you can provide. Rich
