[ossec-list] ADDING NEW AGENTS IN OSSEC INSTALATION IN LOCAL MODE

2016-07-21 Thread Aj Navarro
Im installing OSSEC in LOCAL MODE and i have interesting to adding new agents. How can i do it if the OSSEC Server is in LOCAL MODE? How can i change OSSEC LOCAL MODE to OSSEC SERVER MODE? Its neccesary reinstalling OSSEC in SERVER MODE? -- --- You received this message because you are subsc

[ossec-list] Re: OSSEC 2.8 build on Solaris 10 (Sparc) - "./Makeall all" fails

2016-09-28 Thread Aj Navarro
Do you have an example that how the makeall file is edited. I have OSSEC 2.8.3. and send the next line: # Setting SunOS path if [ "X$OS" = "XSunOS" ]; then PATH=$PATH:/usr/ccs/bin:/usr/xpg4/bin:/opt/csw/gcc3/bin:/opt/csw/bin:/usr/sfw/bin export PATH fi And when I run sh -x Makeall

[ossec-list] OSSEC 2.8.3 in SOLARIS 10 ./MAKEALL ALL failed

2016-09-28 Thread Aj Navarro
Running install.sh in SunOS 5.10 appears the next error message: 5- Installing the system - Running the Makefile ./Makeall: test: argument expected *** Error code 1 The following command caused the error: /bin/sh ./Makeall all make: Fatal error: Command failed for target `all' Error 0x5. Buil

[ossec-list] last -10

2016-10-04 Thread Aj Navarro
i want to monitoring the last connections on a server. I configuring last -10 command on a ossec.conf client full_command last 10 60 I need that the output of this command will send to the ossec server, but I not watching any alert on the ossec wui. can i need to configure a

Re: [ossec-list] last -10

2016-10-05 Thread Aj Navarro
El miércoles, 5 de octubre de 2016, 6:26:42 (UTC-5), dan (ddpbsd) escribió: > > On Tue, Oct 4, 2016 at 6:21 PM, Aj Navarro > wrote: > > i want to monitoring the last connections on a server. > > > > I configuring last -10 command on a ossec.conf client >

[ossec-list] Active response

2016-10-18 Thread Aj Navarro
try to configured the next active response: On Ossec Server: firewall-drop firewall-drop.sh srcip yes no firewall-drop defined-agent 021 5712 1800 On Ossec agent. (id 021) syslog /var/ossec/logs/active-responses.log I made a trial failed a few times the access with r

[ossec-list] Re: RDP Alerts / msauth.xml

2017-07-11 Thread Aj Navarro
Gary... How do you have configure the agent? Some like this? Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational eventchannel Thanks, regards... El lunes, 7 de octubre de 2013, 17:24:38 (UTC-5), Gary White escribió: > I have edited the msauth file so th

[ossec-list] Pivoting in Windws Server

2018-04-25 Thread Aj Navarro
Hi everibody… Can the rootchek function detect pivoting in Windows Server 2008 or 2003? I got Ossec 2.8.3 win32 agent… -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it