[ossec-list] Re: Real-time monitoring and inotify-tools

2012-05-15 Thread mikes
W dniu wtorek, 15 maja 2012 05:02:57 UTC+2 użytkownik Sun Poon napisał: Dear Sir/Madam, Could you please list out the required dependencies for enabling real- time monitoring feature of OSSEC? My server has a specification as below: - SUSE 9 - Linux Kernel 2.6.5-7 - gcc 3.3.3 -

[ossec-list] AnaLogi - OSSEC WUI

2012-05-15 Thread techsupport
Hi, I/We are very happy to announce the release of AnaLogi, an 'Analytical Log Interface' for analysis of database stored OSSEC alerts. This project was started as we could not find any alternative project that met our own requirements, and we love using OSSEC. AnaLogi was built for OSSEC 2.6

Re: [ossec-list] Making OSSEC logging into mysql and not in .log anymore

2012-05-15 Thread secatoor
Well I know that even with unused pid ossec-dbd is working because I can see that it tries to writte to DB (it's logged in mysql.log). Like I told you yesterday, after building database from scratch its working fine, I turned off the computer, started it today and now it isn't working

[ossec-list] logging postgresql-server - how?

2012-05-15 Thread Oliver Jagape
Hi, Im trying to set ossec to monitor postgresql-server logs, upon installation, the rules are only can be found at the ossec server, while on the server that has the ossec agent where also the postgresql-server resides, there is no rules included on the installation. Should I just copy the

Re: [ossec-list] agent-specific agent.conf distribution

2012-05-15 Thread dan (ddp)
On Mon, May 14, 2012 at 6:28 PM, Darrell Hyde darrellh...@gmail.com wrote: I'm in the process of building a file integrity monitoring solution using ossec syscheck. Initially my intention was to use agent.conf to distribute custom rules on a per-customer / per-server basis. What I've discovered

Re: [ossec-list] logging postgresql-server - how?

2012-05-15 Thread dan (ddp)
On Tue, May 15, 2012 at 8:49 AM, Oliver Jagape oliver.jag...@concentrix.com wrote: Hi, Im trying to set ossec to monitor postgresql-server logs, upon installation, the rules are only can be found at the ossec server, while on the server that has the ossec agent where also the

Re: [ossec-list] logging postgresql-server - how?

2012-05-15 Thread Oliver Jagape
thanks for pointing On 05/15/2012 09:05 PM, dan (ddp) wrote: On Tue, May 15, 2012 at 8:49 AM, Oliver Jagape oliver.jag...@concentrix.com wrote: Hi, Im trying to set ossec to monitor postgresql-server logs, upon installation, the rules are only can be found at the ossec server, while on the

RE: [ossec-list] AnaLogi - OSSEC WUI

2012-05-15 Thread James M Pulver
The last link seems to be 404... -- James Pulver LEPP Computer Group Cornell University -Original Message- From: ossec-list@googlegroups.com [mailto:ossec-list@googlegroups.com] On Behalf Of techsupp...@ecsc.co.uk Sent: Tuesday, May 15, 2012 4:55 AM To: ossec-list Subject: [ossec-list]

[ossec-list] Re: AnaLogi - OSSEC WUI

2012-05-15 Thread techsupp...@ecsc.co.uk
Hi James, Many thanks for letting me know... https://github.com/ECSC/analogi/downloads Not sure how I've got downloads at the wrong place in the link ! Andy On Tuesday, 15 May 2012 09:55:17 UTC+1, techs...@ecsc.co.uk wrote: Hi, I/We are very happy to announce the release of AnaLogi, an

Re: [ossec-list] AnaLogi - OSSEC WUI

2012-05-15 Thread Scott Klauminzer
Andy, It looks like the AnaLogi_v1.0.1.zip is not available. AnaLogi_v1.0.1.zip returns a file not found. Scott On May 15, 2012, at 7:38 AM, techsupp...@ecsc.co.uk wrote: Hi James, Many thanks for letting me know... https://github.com/ECSC/analogi/downloads Not sure how I've got

RE: [ossec-list] AnaLogi - OSSEC WUI

2012-05-15 Thread Tom Piersa
his is a great idea. Very much looking forward to checking it out. Tom Thomas Piersa - Programmer Analyst Columbia University, Department of Surgery -Original Message- From: ossec-list@googlegroups.com [mailto:ossec-list@googlegroups.com] On Behalf Of James M Pulver Sent: Tuesday, May

[ossec-list] Re: AnaLogi - OSSEC WUI

2012-05-15 Thread techsupp...@ecsc.co.uk
Sorry for the broken link, I've had real problems with GitHub and their content management the images didn't work at first either. v1.0 - v1.0.1 was extremely minor polishing, so feel free to use v1.0 for now. I will research other hosting solutions in the mean time. Many Thanks Andy On

Re: [ossec-list] AnaLogi - OSSEC WUI

2012-05-15 Thread Steve Lodin
I was able to get code using: https://github.com/ECSC/analogi/zipball/master Looking forward to trying it out. We have approx 1MM events per hour and haven't found a good interface. Steve On Tue, May 15, 2012 at 11:29 AM, Scott Klauminzer sklaumin...@gmail.comwrote: Andy, It looks like

[ossec-list] Re: AnaLogi - OSSEC WUI

2012-05-15 Thread techsupp...@ecsc.co.uk
True, but downloads from the downloads page allows to me get a feel for how many people are trying it out :) That's a lot of alerts Steve! We currently have 1.5 million events over a month (a test setup) and it's responsive on our VM, I hope it's as good for you! On Tuesday, 15 May 2012

Re: [ossec-list] Comma in registry hive names

2012-05-15 Thread Michael Kleinpaste
Yeah. Tried that. Thanks. Did you try a single backslash? I have no idea if it'll work, I don't know if I've ever seen a comma in a registry entry.