Re: [ossec-list] Re: OSSEC & Splunk integration

2010-04-23 Thread Joel Merrick
give it a whirl :) > > > On Thu, Apr 15, 2010 at 8:25 AM, Joel Merrick > wrote: >> >> On Thu, Apr 15, 2010 at 1:22 PM, Joel Merrick >> wrote: >> > Well, it doesn't seem to be displaying anything... >> > >> > OSSEC log directory is be

Re: [ossec-list] Re: OSSEC & Splunk integration

2010-04-15 Thread Joel Merrick
On Thu, Apr 15, 2010 at 1:22 PM, Joel Merrick wrote: > Well, it doesn't seem to be displaying anything... > > OSSEC log directory is being monitored, however sourcetype="ossec" > produced nothing. Files have been indexed. > > Any ideas? Seems as though the string

Re: [ossec-list] Re: OSSEC & Splunk integration

2010-04-15 Thread Joel Merrick
I have this working now, I had to manually add an application, then copy the contents of the tarball... restart.. works! h.t.h. -- $ echo "kpfmAdpoofdufevq/dp/vl" | perl -pe 's/(.)/chr(ord($1)-1)/ge' -- To unsubscribe, reply using "remove me" as the subject.

Re: [ossec-list] Re: OSSEC & Splunk integration

2010-04-15 Thread Joel Merrick
Well, it doesn't seem to be displaying anything... OSSEC log directory is being monitored, however sourcetype="ossec" produced nothing. Files have been indexed. Any ideas? On Thu, Apr 15, 2010 at 1:05 PM, Joel Merrick wrote: > I have this working now, > > I had to man

Re: [ossec-list] Re: OSSEC & Splunk integration

2010-04-15 Thread Joel Merrick
On Thu, Apr 15, 2010 at 12:09 PM, Joel Merrick wrote: > On Wed, Apr 14, 2010 at 10:11 PM, uifjlh wrote: >> Paul, >> >> I seem to have some piece missing my self ? ...  the search part of >> Splunk Works, and I have OSSEC Data there, from my OSSEC clients to >> t

Re: [ossec-list] Re: OSSEC & Splunk integration

2010-04-15 Thread Joel Merrick
On Wed, Apr 14, 2010 at 10:11 PM, uifjlh wrote: > Paul, > > I seem to have some piece missing my self ? ...  the search part of > Splunk Works, and I have OSSEC Data there, from my OSSEC clients to > the OSSEC server, (the same box as the Splunk server) ... but when I > try the OSSEC plugin... thi

Re: [ossec-list] Feature Requests ?

2009-12-30 Thread Joel Merrick
> > Appreciate your response; though as syscheck runs as root it is very hard > to set via limits.conf as it would effect all root processes. I thought > about adding ossec as a supplementary group to root and using that to reset > the priority via limits.conf but I believe it only looks at the pr

Re: [ossec-list] Problem with Centos installation guide

2009-12-23 Thread Joel Merrick
On Wed, Dec 23, 2009 at 12:17 PM, Robert Lourenco wrote: > Hi > > > > The link to installing Ossec on Centos does not work. And my installation > does not work either. > Diagnostics would help :) -- $ echo "kpfmAdpoofdufevq/dp/vl" | perl -pe 's/(.)/chr(ord($1)-1)/ge'

[ossec-list] Re: Week of OSSEC - lots of tips / good information about OSSEC

2009-11-02 Thread Joel Merrick
On Sun, Nov 1, 2009 at 9:14 PM, Michael Starks wrote: > > The presentation is currently in Open Document format. Anyone know of a > way I can add an audio track with the proper timing in an *open* format? > Use vncrec to capture a vnc session and record to theora? -- $ echo "kpfmAdpoofdufevq/d