[ossec-list] server-agent response on command and another question

2011-11-21 Thread Artien Bel
Hello, As test to replace our application and server monitoring software, I am checking out OSSEC. I run at the moment a server/agent installation on 2 VM's with CentOS 5.6 and this works rather well. I do run into some issues though I can't seem to resolve by trying mindlessly, reading the

[ossec-list] SSMTP and sendmail.c

2011-11-21 Thread Jon Schipp
Hello all, I recently replaced a localhost listening sendmail daemon with SSMTP on FreeBSD 8.2. SSMTP does not have the ability to bind to a socket (as for as I know). It's an MTA that transfers mail when another program invokes it. I started using SSMTP for mailing my script outputs because it's

[ossec-list] help with a filesystem_check rule?

2011-11-21 Thread Kat
Hi all.. Just trying to come up with a way to monitor all .ssh folders in / home, but NOT monitor anything else in home. I want to keep an eye on the key files and if they get altered/replaced. I have to think that someone else has wanted to do this before and already has a regex or something?

[ossec-list] decoder fails simple test?

2011-11-21 Thread Kat
What am I missing here? here is the log entry and my very simple decoder just to start and it fails: Oct 31 11:22:05 127.0.0.1 W 5219816637.934 elo_581 213.126.45.119 GET / L/2284/58299/7d/origin-www.freeport.org.adns.net/night.jpg 200 188362153 1 097903 0 ASP/JSP%20source%20code%20leakage

[ossec-list] Re: decoder fails simple test?

2011-11-21 Thread Kat
why is there no way to delete a post you put up when you realize you made stupid mistakes? Can someone delete this please. Moderators? Yeah, I guess it would help if I realized some obvious things like my fields and characters, etc. DOH! On Nov 21, 1:38 pm, Kat uncommon...@gmail.com wrote: What