A little further, I changed the logformat from eventlog to eventchannel, and now the archive.log has taken out all of the multiple lines. I still do not have a generated alert yet even though ossec-logtest says it generates an alert and it matches my custom rule. I set the level to level 6.
On Friday, November 27, 2015 at 8:41:48 AM UTC-6, Phillipa Moorea wrote: > > Well, I updated both the server and client OSSEC HIDS to 2.8.3, but still > no luck. The PowerShell logs in archive.log are still multi-line logs, and > I am getting the same results. > > On Wednesday, November 25, 2015 at 8:45:18 AM UTC-6, Phillipa Moorea wrote: >> >> Ok, I think I know what's going on now. I do not have the latest stable >> release of 2.8.3. I think I might have 2.8.2 or 2.8.1 or something. >> >> I found this issue which resembled my issue because the logs have >> multiple lines in powershell. >> https://github.com/ossec/ossec-hids/issues/224 >> Then I saw that a fix was implemented in 2.9 from here: >> https://github.com/ossec/ossec-hids/pull/457 >> Then from this forum I now see that perhaps it is implemented in 2.8.3 on >> Nov 5th which is probably the day after I had made my OSSEC updates, lol: >> https://groups.google.com/forum/#!topic/ossec-list/JA9x4uzDg1g >> >> I'll try updating to the latest version again and see if that helps. >> >> On Monday, November 9, 2015 at 9:17:28 AM UTC-6, Phillipa Moorea wrote: >>> >>> I have restarted OSSEC using the OSSEC Agent Manager on the ossec client >>> computer. I have also restarted the OSSEC service on the OSSEC server. >>> I'm not sure why I can't reply to your response, so I had to reply to mine >>> @dan(ddpbsd) >>> >>> Also I am using OSSEC HIDS v2.8 on the client & server. >>> >> -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout.
