Perfect that worked great. Any way we could get that into the next update? Thanks for your help!!
Rich Rich Houston wrote: > Hi all, > > I have recently upgraded a firewall I manage from CentOS 4.x to Ubuntu > 10.04 based system, I have installed the latest from repos Shorewall > and the latest Ossec 2.5.1. > > Under the old system drops and redirects were logged and Ossec would > report them to me via email. Now this does not happen. I can see the > Shorewall entries in the /var/log/messages file as expected but Ossec > will not report them to me. I now have 2 servers that do the same > thing. I have attached entries from one firewall that is working and > one that does not. > > This one is working: > > Oct 27 10:07:20 gateway kernel: Shorewall:loc2all:ACCEPT:IN=eth1 > OUT=XXX SRC=XXX.XXX.XXX.XXX DST=XXX.XXX.XXX.XXX LEN=78 TOS=0x00 > PREC=0x00 TTL=63 ID=22537 PROTO=UDP SPT=XXX DPT=XXX LEN=58 > > This in CentOS 4.X with Ossec 2.4.1 > > This one is not: > > Oct 27 10:08:12 localhost kernel: [139017.036739] > Shorewall:loc2fw:ACCEPT:IN=eth1 OUT= > MAC=---------------------------------------- SRC=xxx.xxx.xxx.xxx > DST=xxx.xxx.xxx.xxx LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=29371 DF > PROTO=TCP SPT=40876 DPT=3128 WINDOW=5840 RES=0x00 SYN URGP=0 > > This one is on Ubuntu 10.04 with Ossec 2.5.1 > > Could the [139017.036739] in the second entries be the issue and the > decoder regx is getting confused? I though that Ossec looked for the > program in the 3 field? Sorry if that is way off base? > > Thanks for any help you can provide. > > Rich
