[ossec-list] Whitelisting netblocks

2009-03-20 Thread NCUB
Hi - I'm wondering if whitelisting netblocks works? I tried it, and my IP was still blocked after reloading. It's blocking me for using phpMyAdmin. Am I doing this wrong (example beow). Thanks! Beth 127.0.0.1 ^localhost.localdomain$ 192.168.0.0/24 OSSEC HIDS Notification.

[ossec-list] Re: Specify LISTEN IP and/or interface on the server?

2009-03-20 Thread Mark C
Hi Daniel, When the server uses local_ip x.x.150.139 (virtual interface) and a client on a different network is set to contact the server on x.x. 150.139: 10:13:24.789953 IP xxx.xxx.135.169.32862 > xxx.xxx.150.139.1514: UDP, length 73 10:13:24.791055 IP xxx.xxx.150.137.1514 > xxx.xxx.135.169.328

[ossec-list] Re: OSSEC Report

2009-03-20 Thread Martin Tartarelli
matthias/Daniel, 2009/3/16 matthias platzer : > > On Mar 16, 7:06 pm, Martin Tartarelli > wrote: > >> > What version of ossec are you using? It comes by default on v2.0. >> >> I Have v.1.6.1. In that version.can i use this features? > > No, it is a new feature since v2.0. > >> Can I install

[ossec-list] Re: generating proxy(squid) statistics and reporting....

2009-03-20 Thread Daniel Callan
Hi khmadhu khmadhu wrote: > I have installed the ossec server on linux. I have a log file which > is generated by a proxy server. its arround 400 MB .i want to generate > the statistics of that log only, like TCP_HIT,TCP_REFRESH etc.. > downloads,top sites,in graph.. > I routinely generate exa

[ossec-list] Re: BIG PROBLEM - runaway syscheckd process

2009-03-20 Thread Nerijus Krukauskas
On 19/03/2009, John A. Sullivan III wrote: > > Thanks, Daniel. I have the trace but it is a 40 MB file. How shall I > send it to you? - John I believe that if you try to zip it, it's gonna be something around 4 MB... :) -- http://nk99.org/