Re: [ossec-list] Re: OSSEC large scale deployment

2012-05-23 Thread Zate
Yeah I dont see a problem with sharing it. Nate actually did most of it, and we are still tweaking it a little but give me a week or so to get the bugs out and I dont mind sharing. Zate On Wed, May 23, 2012 at 9:23 AM, sklaumin...@gmail.com < sklaumin...@gmail.com> wrote: > Zate, > > I would l

Re: [ossec-list] Re: OSSEC large scale deployment

2012-05-23 Thread sklaumin...@gmail.com
Zate, I would love to see the ruleset you've come up with for Windows. I've been trying to out the time towards this, but have not been able to yet. Would you be willing to share what you've come up with? Scott Klauminzer Director of Information Technology & Security Sent from my iPad On May

Re: [ossec-list] Problem with service ossec-dbd

2012-05-23 Thread dan (ddp)
On Wed, May 23, 2012 at 8:08 AM, Emmanuel E. wrote: > Hello, I have a problem with the database of OSSEC, ossec-dbd, because the > same stops unexpectedly, while that the mysql is working properly. When I > restart ossec, this service start correctly. > Keeping track of the states through which it

Re: [ossec-list] Re: agent cannot connect to server

2012-05-23 Thread dan (ddp)
What version of OSSEC (on server and agent)? Has the agent ever successfully communicated with the server? Run tcpdump on the server. Can you see the udp packets arriving on port 1514? Do you see response packets back to the agent? Are the packets from the agent coming in from the correct IP (the

Re: [ossec-list] Re: agent cannot connect to server

2012-05-23 Thread dan (ddp)
On Wed, May 23, 2012 at 4:56 AM, hoa nguyen wrote: > > Hi, > > I has deleted rids and renew agent for XP. > But this problem is still. > sometimes. there are error: > "Error message Unofrmatting from x.x.x.x" This message does not appear in the source tree at all. Please provide the exact error m

[ossec-list] Problem with service ossec-dbd

2012-05-23 Thread Emmanuel E.
Hello, I have a problem with the database of OSSEC, ossec-dbd, because the same stops unexpectedly, while that the mysql is working properly. When I restart ossec, this service start correctly. Keeping track of the states through which it passes ossec, fail to see the following: first: ossec: o

[ossec-list] Re: agent cannot connect to server

2012-05-23 Thread mikes
tcpdump udp host ? W dniu środa, 23 maja 2012 11:26:02 UTC+2 użytkownik hoa nguyen napisał: > > I'd tried. > But this problem isn't OK yet. > > Ubuntu and XP virtual machine, two node communicate via NIC eth0 > Please help me a solution > Thanks > > Hoa > > On May 23, 3:16 pm, mikes wrote:

[ossec-list] Re: agent cannot connect to server

2012-05-23 Thread hoa nguyen
I'd tried. But this problem isn't OK yet. Ubuntu and XP virtual machine, two node communicate via NIC eth0 Please help me a solution Thanks Hoa On May 23, 3:16 pm, mikes wrote: > Try it: > > /etc/init.d/ossec stop > rm /var/ossec/queue/rids/* > /etc/init.d/ossec start > > And check key for agen

[ossec-list] Re: agent cannot connect to server

2012-05-23 Thread hoa nguyen
Hi, I has deleted rids and renew agent for XP. But this problem is still. sometimes. there are error: "Error message Unofrmatting from x.x.x.x" Please you help me for solution? Thanks again Hoa On May 23, 3:16 pm, mikes wrote: > Try it: > > /etc/init.d/ossec stop > rm /var/ossec/queue/rids/*

[ossec-list] Re: agent cannot connect to server

2012-05-23 Thread mikes
Try it: /etc/init.d/ossec stop rm /var/ossec/queue/rids/* /etc/init.d/ossec start And check key for agent. Try remove agent from server and generate new key, remember delete rids/* after W dniu środa, 11 kwietnia 2012 09:59:41 UTC+2 użytkownik jack@gmail.com napisał: > > Hi, > I have oss

[ossec-list] Re: agent cannot connect to server

2012-05-23 Thread hoa nguyen
Hi, I have a same problem to you. I have ossec server on ubuntu, and a agent on XP (virtual macine on ubuntu). My agent can not connect to server. Please help me fot solution. Thanks very much Hoa On Apr 11, 9:08 pm, "dan (ddp)" wrote: > I think the rids files are named after theagentid number