Hi,

I have a centralized syslog that contains logs from Windows and Unix hosts
(and devices).  The logs are all single line logs, but with different
signatures.

E.g. the windows event log format is
Sep 18 00:01:06 TXXXXXX2.syxxxxxd.com MSWinEventLog .......

A sample unix log format is
Sep 18 00:01:02 10.111.114.88 sshd:  .....

I have setup ossec to read the file and specified the <log_format> as
"syslog".

However, whenever ossec comes across the windows event logs, it throws an
alert "Unknown problem somewhere in the system".

I went through the syslog_rules.xml and found that this error is caused
because the log is not in the format supported by the syslog decoder.

Is there anyway I can get ossec to read the log line and check which decoder
matches the log before processing the log?

Thanks and regards,
Chris



On Tue, Oct 5, 2010 at 2:58 PM, Christopher Moraes <[email protected]>wrote:

> Hi,
>
> We're using syslog-ng to centralize logs on a server.   The way the system
> is setup is that *all* system logs (for unix, windows, apache, iis, etc) get
> written to a single file on the syslog server.
>
> Can OSSEC be configured to analyse this type of combined syslog file?
>
> Regards,
> Chris
>
>
>
>

Reply via email to