It's possible. ;) I'll try to sneak it into my tree and bug dcid about it again.
Thanks for the report BTW. On Thu, Oct 28, 2010 at 5:43 PM, Rich Houston <[email protected]> wrote: > Perfect that worked great. Any way we could get that into the next > update? > > Thanks for your help!! > > Rich > > Rich Houston wrote: >> Hi all, >> >> I have recently upgraded a firewall I manage from CentOS 4.x to Ubuntu >> 10.04 based system, I have installed the latest from repos Shorewall >> and the latest Ossec 2.5.1. >> >> Under the old system drops and redirects were logged and Ossec would >> report them to me via email. Now this does not happen. I can see the >> Shorewall entries in the /var/log/messages file as expected but Ossec >> will not report them to me. I now have 2 servers that do the same >> thing. I have attached entries from one firewall that is working and >> one that does not. >> >> This one is working: >> >> Oct 27 10:07:20 gateway kernel: Shorewall:loc2all:ACCEPT:IN=eth1 >> OUT=XXX SRC=XXX.XXX.XXX.XXX DST=XXX.XXX.XXX.XXX LEN=78 TOS=0x00 >> PREC=0x00 TTL=63 ID=22537 PROTO=UDP SPT=XXX DPT=XXX LEN=58 >> >> This in CentOS 4.X with Ossec 2.4.1 >> >> This one is not: >> >> Oct 27 10:08:12 localhost kernel: [139017.036739] >> Shorewall:loc2fw:ACCEPT:IN=eth1 OUT= >> MAC=---------------------------------------- SRC=xxx.xxx.xxx.xxx >> DST=xxx.xxx.xxx.xxx LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=29371 DF >> PROTO=TCP SPT=40876 DPT=3128 WINDOW=5840 RES=0x00 SYN URGP=0 >> >> This one is on Ubuntu 10.04 with Ossec 2.5.1 >> >> Could the [139017.036739] in the second entries be the issue and the >> decoder regx is getting confused? I though that Ossec looked for the >> program in the 3 field? Sorry if that is way off base? >> >> Thanks for any help you can provide. >> >> Rich
