It's possible. ;)

I'll try to sneak it into my tree and bug dcid about it again.

Thanks for the report BTW.

On Thu, Oct 28, 2010 at 5:43 PM, Rich Houston <[email protected]> wrote:
> Perfect that worked great. Any way we could get that into the next
> update?
>
> Thanks for your help!!
>
> Rich
>
> Rich Houston wrote:
>> Hi all,
>>
>> I have recently upgraded a firewall I manage from CentOS 4.x to Ubuntu
>> 10.04 based system, I have installed the latest from repos Shorewall
>> and the latest Ossec 2.5.1.
>>
>> Under the old system drops and redirects were logged and Ossec would
>> report them to me via email. Now this does not happen. I can see the
>> Shorewall entries in the /var/log/messages file as expected but Ossec
>> will not report them to me. I now have 2 servers that do the same
>> thing. I have attached entries from one firewall that is working and
>> one that does not.
>>
>> This one is working:
>>
>> Oct 27 10:07:20 gateway kernel: Shorewall:loc2all:ACCEPT:IN=eth1
>> OUT=XXX SRC=XXX.XXX.XXX.XXX DST=XXX.XXX.XXX.XXX LEN=78 TOS=0x00
>> PREC=0x00 TTL=63 ID=22537 PROTO=UDP SPT=XXX DPT=XXX LEN=58
>>
>> This in CentOS 4.X with Ossec 2.4.1
>>
>> This one is not:
>>
>> Oct 27 10:08:12 localhost kernel: [139017.036739]
>> Shorewall:loc2fw:ACCEPT:IN=eth1 OUT=
>> MAC=---------------------------------------- SRC=xxx.xxx.xxx.xxx
>> DST=xxx.xxx.xxx.xxx LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=29371 DF
>> PROTO=TCP SPT=40876 DPT=3128 WINDOW=5840 RES=0x00 SYN URGP=0
>>
>> This one is on Ubuntu 10.04 with Ossec 2.5.1
>>
>> Could the [139017.036739] in the second entries be the issue and the
>> decoder regx is getting confused? I though that Ossec looked for the
>> program in the 3 field? Sorry if that is way off base?
>>
>> Thanks for any help you can provide.
>>
>> Rich

Reply via email to