Re: [ossec-list] How change agent list order in ossec wui v. 0.8

2015-05-22 Thread Daniil Svetlov
Hi! It seems that ossec wui not supporting and developing. You can try https://github.com/dsvetlov/lightsiem I can answer any about it. пт, 22 мая 2015, 12:39, Grzegorz Prokopowicz cdsi...@gmail.com: How change agent agent list order ? Need to see them in alphabetical order in ossec wui

[ossec-list] Re: wget download forbidden

2015-05-22 Thread Patrick Morton
Thank you! On Tuesday, August 26, 2014 at 6:12:02 PM UTC-5, Joe Evango wrote: Hello, This works for me: wget -U ossec http://www.ossec.net/files/ossec-hids-2.8.tar.gz On Tuesday, July 29, 2014 6:30:38 AM UTC-7, Jan Andrasko wrote: Hi guys, today, when trying to download ossec from

[ossec-list] Jak zmienić kolejność agentów wyświetlanych w WUI Osseca.

2015-05-22 Thread Grzegorz Prokopowicz
Jak zmienić kolejność agentów wyświetlanych w WUI Osseca ? Potrzebuje zmiany aby agenty były listowane w kolejności alfabetycznej. WUI wersja 0.8 Za wszelką pomoc dziękuje ... -- --- You received this message because you are subscribed to the Google Groups ossec-list group. To unsubscribe

[ossec-list] How change agent list order in ossec wui v. 0.8

2015-05-22 Thread Grzegorz Prokopowicz
How change agent agent list order ? Need to see them in alphabetical order in ossec wui v.0,8 Help please if possible :) -- --- You received this message because you are subscribed to the Google Groups ossec-list group. To unsubscribe from this group and stop receiving emails from it, send

Re: [ossec-list] Having OSSEC run a script instead of send an email ???

2015-05-22 Thread Ryan
Have a look at active responses in OSSEC: http://ossec-docs.readthedocs.org/en/latest/manual/ar/ar-custom.html [2] In a nutshell you define a command to be run with command and you define when (and where) it should be triggered with active-response On 2015-05-21 13:04, caplinu...@gmail.com

Re: [ossec-list] Re: Having OSSEC run a script instead of send an email ???

2015-05-22 Thread dan (ddp)
On Thu, May 21, 2015 at 2:40 PM, caplinu...@gmail.com wrote: Ok So i figured out my own question, i will go ahead and use make custom active response rules to run my script: http://ossec-docs.readthedocs.org/en/latest/manual/ar/ar-custom.html If that doesn't do all you need, you could also

Re: [ossec-list] Active Response in windows 2008

2015-05-22 Thread dan (ddp)
On Sun, May 17, 2015 at 3:36 AM, HMath h.i.youss...@gmail.com wrote: another point, there are some system errors in windows machine I saw them in log file in windows ossec Errors could be bad. I didn't check, but are you sure all of the rule IDs you added to the AR configuration have source

Re: [ossec-list] How to install/configure agent on OSSEC server?

2015-05-22 Thread dan (ddp)
On Tue, May 19, 2015 at 6:41 PM, Ryan Wendel ryan.wen...@gmail.com wrote: I'm working through how to use OSSEC and am humming along nicely. The one thing I haven't figured out yet is how to run an agent on the OSSEC server itself. Do I need to perform a separate installation? On Redhat I

Re: [ossec-list] CDB files - ignore case?

2015-05-22 Thread dan (ddp)
On Wed, May 20, 2015 at 3:48 PM, Brian Kellogg thefla...@gmail.com wrote: Is there a way to force OSSEC to ignore case on CDB lookups? Not all logs convert usernames to lowercase unfortunately. I'm not aware of any options to do this. thanks, Brian -- --- You received this message

Re: [ossec-list] Different checks for nested directories

2015-05-22 Thread dan (ddp)
On Tue, May 19, 2015 at 11:16 AM, Steve MacDougall smacdoug...@bluepay.com wrote: There are cases where I'd like to perform different checks on the parent directory than on the nested directories. For example, 'check all' on /var. but check only ownership and permissions on /var/lib/postgresql.

Re: [ossec-list] Re: Ossec iis log recognize problem

2015-05-22 Thread dan (ddp)
On Wed, May 20, 2015 at 5:36 PM, Brent Morris brent.mor...@gmail.com wrote: So to get IIS to work right, I had to go into IIS Manager, click on Default Web Site (or appropriate site) open the properties window for Logging. Select the W3C format. Click Select Fields and check every box on that

Re: [ossec-list] Creating a rule to find SSH keys in authlog with VERBOSE turned on

2015-05-22 Thread dan (ddp)
On Thu, May 21, 2015 at 2:38 PM, caplinu...@gmail.com wrote: Hello all, I am trying to write a rule in OSSEC to look at /var/log/authlog and alert on lines that show a RSA key. In my environment we only use ssh keys to remote on and when somebody login via root i would like OSSEC to show the

Re: [ossec-list] CDB files - ignore case?

2015-05-22 Thread Brian Kellogg
Thanks, I just wrote a Python script that populates the file with all upper and lowercase permutations. Makes for a big file for some of our CDBs but it does the job. -- --- You received this message because you are subscribed to the Google Groups ossec-list group. To unsubscribe from this

[ossec-list] plugin

2015-05-22 Thread Brent Wegmann
Does anyone have a netmotion mobility plugin Brent -- --- You received this message because you are subscribed to the Google Groups ossec-list group. To unsubscribe from this group and stop receiving emails from it, send an email to ossec-list+unsubscr...@googlegroups.com. For more options,