[ossec-list] Can use OSSEC for FIM solution ,

2015-02-10 Thread shankey
HI TEAm ,
 
Can is use OSSEC for FIM solution, to clear my PCI Audit, if yes, then help 
me with the hardware requirement and installation procedure.
 
Regards
Shankey 

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to ossec-list+unsubscr...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


Re: [ossec-list] Can use OSSEC for FIM solution ,

2015-02-10 Thread Kevin Wilcox
On 10 February 2015 at 11:42, shankey  wrote:
> HI TEAm ,
>
> Can is use OSSEC for FIM solution, to clear my PCI Audit, if yes, then help
> me with the hardware requirement and installation procedure.
>
> Regards
> Shankey
>
> --
>
> ---
> You received this message because you are subscribed to the Google Groups
> "ossec-list" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to ossec-list+unsubscr...@googlegroups.com.
> For more options, visit https://groups.google.com/d/optout.

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to ossec-list+unsubscr...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


Re: [ossec-list] Can use OSSEC for FIM solution ,

2015-02-10 Thread dan (ddp)
On Tue, Feb 10, 2015 at 11:42 AM, shankey  wrote:
> HI TEAm ,
>
> Can is use OSSEC for FIM solution, to clear my PCI Audit, if yes, then help
> me with the hardware requirement and installation procedure.
>

OSSEC's syscheck functionality provides some file integrity monitoring
capabilities: 
http://ossec-docs.readthedocs.org/en/latest/manual/syscheck/index.html

> Regards
> Shankey
>
> --
>
> ---
> You received this message because you are subscribed to the Google Groups
> "ossec-list" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to ossec-list+unsubscr...@googlegroups.com.
> For more options, visit https://groups.google.com/d/optout.

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to ossec-list+unsubscr...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


Re: [ossec-list] Can use OSSEC for FIM solution ,

2015-02-10 Thread Kevin Wilcox
On 10 February 2015 at 11:44, Kevin Wilcox  wrote:

> On 10 February 2015 at 11:42, shankey  wrote:

>> Can is use OSSEC for FIM solution, to clear my PCI Audit, if yes, then help
>> me with the hardware requirement and installation procedure.

Sorry about the blank reply, folks, the "..." and the "Send" in Gmail
are too close together on my laptop screen.

Shankey - yes, there are people who are successfully using OSSEC to
meet the FIM requirements in PCI.

Your hardware requirements and the installation process will depend on
the number of clients you're deploying. You will need to tune it to
your environment by modifying the directories and files to be
monitored (and whether you need that monitoring to happen in
real-time).

kmw

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to ossec-list+unsubscr...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


Re: [ossec-list] Can use OSSEC for FIM solution ,

2015-02-10 Thread shankey
HI Team,
 
There are arrount 500 server which need to be monitor through (Manager 
OSSEC server) we would requred all system and application logs for the 
audit and complaince.
base on the that can you suggest how should i go ahead.
 
it would be great if you can share the steps by steps process and hardware 
spec to implement the same in our environment.
 
 
FYI :- i not very much familier with the linux.
 
 
 
 

On Tuesday, February 10, 2015 at 10:18:44 PM UTC+5:30, thefergus wrote:

> On 10 February 2015 at 11:44, Kevin Wilcox  > wrote: 
>
> > On 10 February 2015 at 11:42, shankey > 
> wrote: 
>
> >> Can is use OSSEC for FIM solution, to clear my PCI Audit, if yes, then 
> help 
> >> me with the hardware requirement and installation procedure. 
>
> Sorry about the blank reply, folks, the "..." and the "Send" in Gmail 
> are too close together on my laptop screen. 
>
> Shankey - yes, there are people who are successfully using OSSEC to 
> meet the FIM requirements in PCI. 
>
> Your hardware requirements and the installation process will depend on 
> the number of clients you're deploying. You will need to tune it to 
> your environment by modifying the directories and files to be 
> monitored (and whether you need that monitoring to happen in 
> real-time). 
>
> kmw 
>

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to ossec-list+unsubscr...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


Re: [ossec-list] Can use OSSEC for FIM solution ,

2015-02-10 Thread Eero Volotinen
2015-02-10 18:42 GMT+02:00 shankey :

> HI TEAm ,
>
> Can is use OSSEC for FIM solution, to clear my PCI Audit, if yes,
>

Yes, it can act as fim.


> then help me with the hardware requirement and installation procedure.
>

Err. Maybe you need to hire consult ..

--
Eero

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to ossec-list+unsubscr...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


Re: [ossec-list] Can use OSSEC for FIM solution ,

2015-02-11 Thread shankey
HOW server and client communicate? what are the port that need to be open ?
 
Can we use some other port for client to server communication.
 

On Tuesday, February 10, 2015 at 11:06:44 PM UTC+5:30, Eero Volotinen wrote:

>
>
> 2015-02-10 18:42 GMT+02:00 shankey >:
>
>>  HI TEAm ,
>>  
>> Can is use OSSEC for FIM solution, to clear my PCI Audit, if yes, 
>>
>
> Yes, it can act as fim.
>  
>
>>  then help me with the hardware requirement and installation procedure.
>>
>
> Err. Maybe you need to hire consult ..
>
> --
> Eero 
>
>  
>

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to ossec-list+unsubscr...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


Re: [ossec-list] Can use OSSEC for FIM solution ,

2015-02-11 Thread Eero Volotinen
2015-02-11 12:42 GMT+02:00 shankey :

>
> HOW server and client communicate? what are the port that need to be open ?
>
> Can we use some other port for client to server communication.
>
>
>
HOW about reading the *docs* first?

--
Eero

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to ossec-list+unsubscr...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


Re: [ossec-list] Can use OSSEC for FIM solution ,

2015-02-11 Thread Craig Lawson
1514 UDP as default, but please read the docs 
- http://ossec-docs.readthedocs.org/en/latest/


On Wednesday, 11 February 2015 10:42:25 UTC, shankey wrote:
>
> HOW server and client communicate? what are the port that need to be open ?
>  
> Can we use some other port for client to server communication.
>  
>
> On Tuesday, February 10, 2015 at 11:06:44 PM UTC+5:30, Eero Volotinen 
> wrote:
>
>>
>>
>> 2015-02-10 18:42 GMT+02:00 shankey :
>>
>>>  HI TEAm ,
>>>  
>>> Can is use OSSEC for FIM solution, to clear my PCI Audit, if yes, 
>>>
>>
>> Yes, it can act as fim.
>>  
>>
>>>  then help me with the hardware requirement and installation procedure.
>>>
>>
>> Err. Maybe you need to hire consult ..
>>
>> --
>> Eero 
>>
>>  
>>
>

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to ossec-list+unsubscr...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.