That's correct, using the WUI which is where it displays incorrectly, the 
alerts.log file has the correct username though.

OSSEC HIDS 2.6 according to *./ossec-analysisd -V*

On Tuesday, 9 December 2014 23:45:06 UTC+11, dan (ddpbsd) wrote:
>
> On Mon, Dec 8, 2014 at 7:11 PM, Jarrod Farncomb <[email protected] 
> <javascript:>> wrote: 
> > Hey all, bit of a strange issue here.. If I log in/out of a server the 
> event 
> > will be logged into the alerts.log file perfectly fine, but when viewing 
> the 
> > logs in a browser through the web interface the Src IP field lists the 
> > username but it does so incorrectly, it appears that the first character 
> is 
> > always truncated and does not display. 
> > 
> > This only happens when outputting to the web page, the name in full 
> > correctly displays in the alerts.log file so I'm thinking it's to do 
> with 
> > the parsing/regex of the alerts.log file, though I am not sure where and 
> > have not been able to see where Src IP is doing this? I thought it'd 
> have 
> > been srcuser displayed but the name with the first letter missing always 
> > shows on Src IP? 
> > 
>
> I'm guessing you're using the WUI? Which version? Which version of OSSEC? 
>
> > -- 
> > 
> > --- 
> > You received this message because you are subscribed to the Google 
> Groups 
> > "ossec-list" group. 
> > To unsubscribe from this group and stop receiving emails from it, send 
> an 
> > email to [email protected] <javascript:>. 
> > For more options, visit https://groups.google.com/d/optout. 
>

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to