Re: [ossec-list] Log firewall changes

2020-02-18 Thread dan (ddp)
On Tue, Feb 18, 2020 at 1:52 AM Schultheis Burkhard wrote: > > Hi, > > I want to get a message, when the ruleset of iptables gets modified. But > I see that iptables doesn't log its changes. Or am I wrong? > I'm not aware of a log, but I'm far from an expert. If you're running an OSSEC agent on

Re: [ossec-list] Log firewall changes

2020-02-17 Thread Schultheis Burkhard
Hi, I want to get a message, when the ruleset of iptables gets modified. But I see that iptables doesn't log its changes. Or am I wrong? Thanks! Regards Burkhard Am 17.02.2020 um 16:20 schrieb dan (ddp): On Mon, Feb 17, 2020 at 9:25 AM Burkhard Schultheis wrote: Hi, I want to get an

Re: [ossec-list] Log firewall changes

2020-02-17 Thread dan (ddp)
On Mon, Feb 17, 2020 at 9:25 AM Burkhard Schultheis wrote: > > Hi, > > I want to get an email from OSSEC when a port is opened or closed in the > firewall. Therefore I changed "no_log" in firewall_rules.xml to "log". > But the OSSEC failed to start. What's wrong? How to get the desired > emails

[ossec-list] Log firewall changes

2020-02-17 Thread Burkhard Schultheis
Hi, I want to get an email from OSSEC when a port is opened or closed in the firewall. Therefore I changed "no_log" in firewall_rules.xml to "log". But the OSSEC failed to start. What's wrong? How to get the desired emails for firewall changes? It's OSSEC v3.3.0 on CentOS 6.10. Thanks in