I've never see DDP logs. Do you have an example of the logs from DDP that you expect OSSEC to decode and generate alerts for? Or have you tried feeding the logs into /var/ossec/bin/ossec-logtest yourself and seeing if OSSEC can decode them?

I assume that if it is standard syslog format, you will only need to create some rules for stuff you want to trigger alerts. If you send it via netconsole you might need a decoder too to read the kernel log format (I don't remember if there is a decoder for kernel messages in the default setup or not, but writing one would be easy if it comes to that).

On 10/20/2015 5:02 AM, Tino Zidore wrote:
I have talked to the supporter for the DDP and they suggest netconsole to be able to get kernel logs even if the machine has crashed.

Does Ossec work with netconsole?

Here is the message from the supporter:
/What I suggested to extend logging with the Linux 'netconsole' feature. That are kernel messages send out over UDP and also work during a kernel crash (till panic where all stops)./
--

---
You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected] <mailto:[email protected]>.
For more options, visit https://groups.google.com/d/optout.

--

--- You received this message because you are subscribed to the Google Groups "ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

Reply via email to