Re: [ossec-list] install ossec-agent trough puppet

2012-11-28 Thread rezgui mohamed
thanks, have an idea hw do teh configuration of agent : past the key, change the file ossec.conf for the agent trough puppet? Best regards

Re: [ossec-list] install osecc-agent

2012-11-28 Thread rezgui mohamed
Thanks, i have a puppet and the OS of client is debian. Best regards

Re: [ossec-list] ossec-syscheckd consumes more cpu space and make apache to down

2012-11-28 Thread Yesodha
Hi, Can anyone response this ticket?Still i am facing this issue. Regards, Yesodha Prabhu On Wednesday, October 10, 2012 2:23:23 PM UTC+5:30, Yesodha wrote: No,I didn't do any syscheck tuning. Regards, Yesodha P On Thursday, October 4, 2012 6:35:02 PM UTC+5:30, dan (ddpbsd) wrote: On

Re: [ossec-list] ossec-syscheckd consumes more cpu space and make apache to down

2012-11-28 Thread Ryan Schulze
Are you sure your CPU is your bottleneck? How does it behave after tuning the syscheck options? On 11/28/2012 5:11 AM, Yesodha wrote: Hi, Can anyone response this ticket?Still i am facing this issue. Regards, Yesodha Prabhu On Wednesday, October 10, 2012 2:23:23 PM UTC+5:30, Yesodha wrote:

[ossec-list] Agent configuration management via central server

2012-11-28 Thread funwithossec
All, Apologies if this has been covered, but I sure couldn't find it :-) In my lab I have a central ossec 2.6 server on Ubuntu and one client on Centos, set them up with active response and followed procedure here: http://www.ossec.net/doc/manual/agent/agent-configuration.html

Re: [ossec-list] Agent configuration management via central server

2012-11-28 Thread dan (ddp)
On Tue, Nov 27, 2012 at 7:29 PM, funwithossec h...@donobi.net wrote: All, Apologies if this has been covered, but I sure couldn't find it :-) In my lab I have a central ossec 2.6 server on Ubuntu and one client on Centos, set them up with active response and followed procedure here:

Re: [ossec-list] ossec-syscheckd consumes more cpu space and make apache to down

2012-11-28 Thread dan (ddp)
On Wed, Nov 28, 2012 at 6:11 AM, Yesodha yeso...@easylinkindia.com wrote: Hi, Can anyone response this ticket?Still i am facing this issue. Regards, Yesodha Prabhu This isn't a ticket, and the response was to tune syscheck. On Wednesday, October 10, 2012 2:23:23 PM UTC+5:30, Yesodha

Re: [ossec-list] ossec-syscheckd consumes more cpu space and make apache to down

2012-11-28 Thread Yesodha S
Hi, During the syscheck tuning,the cpu load becomes 97 and gradually it goes to normal load.During that time,sometimes server itself went down or sometimes apache down. Regards, Yesodha On Wed, Nov 28, 2012 at 6:11 PM, Ryan Schulze r...@dopefish.de wrote: Are you sure your CPU is your

[ossec-list] VMWare ESX - CIS Checks

2012-11-28 Thread Mike Disley
Greetings, Under Supported Systems, Operating systems, on the OSSEC site there is a reference to VMWare ESX 3.0,3.5 (including CIS checks). Is there a list online of those CIS checks for VMWare that OSSEC does? Please and Thanks, Mike

[ossec-list] Routing communication between agent and server via TCP

2012-11-28 Thread Nikhil Dewan
I am using following socat commands to meet my requirement : to route logs via TCP to server Agent machine : socat udp4-recvfrom:1514,reuseaddr,fork tcp4:10.85.203.175: Server machine : socat tcp4-listen:,reuseaddr,fork udp4:localhost:1514 Sets the ossec server ip as

Re: [ossec-list] VMWare ESX - CIS Checks

2012-11-28 Thread dan (ddp)
On Wed, Nov 28, 2012 at 9:00 AM, Mike Disley mike.a.dis...@tpsgc-pwgsc.gc.ca wrote: Greetings, Under Supported Systems, Operating systems, on the OSSEC site there is a reference to VMWare ESX 3.0,3.5 (including CIS checks). Is there a list online of those CIS checks for VMWare that OSSEC

Re: [ossec-list] VMWare ESX - CIS Checks

2012-11-28 Thread dan (ddp)
On Wed, Nov 28, 2012 at 9:57 AM, Mike Disley mike.a.dis...@tpsgc-pwgsc.gc.ca wrote: Excellent, thanks Dan. Last question I see the RHEL5 file (cis_rhel5_linux_rcl.txt) in the /etc/shared directory. Are there any plans to expand the CIS checks to include SUSE or SLES distributions or

Re: [ossec-list] Re: report_changes=yes not reporting diffs in alerts

2012-11-28 Thread dan (ddp)
On Wed, Nov 28, 2012 at 10:01 AM, mcrane0 mathew.cr...@gmail.com wrote: ossec.conf on server, relevant portion: directories report_changes=yes check_all=yes/etc,/var/ossec/etc/directories directories check_all=yes/usr/bin,/usr/sbin/directories directories

Re: [ossec-list] Re: report_changes=yes not reporting diffs in alerts

2012-11-28 Thread Mathew Crane
Bah, it must not have pushed out the agent.conf on the server. Thanks. On Wed, Nov 28, 2012 at 9:35 AM, dan (ddp) ddp...@gmail.com wrote: On Wed, Nov 28, 2012 at 10:01 AM, mcrane0 mathew.cr...@gmail.com wrote: ossec.conf on server, relevant portion: directories report_changes=yes

Re: [ossec-list] Re: report_changes=yes not reporting diffs in alerts

2012-11-28 Thread mcrane0
Upon review, that's the non-testing env. Apologies for the confusion. Here is where it's not working: /agent_config agent_config os=Linux syscheck frequency86400/frequency scan_on_startyes/scan_on_start scan_time03:00/scan_time auto_ignoreno/auto_ignore !-- Directories

Re: [ossec-list] Agent configuration management via central server

2012-11-28 Thread Kat
If I am reading your problem - you are saying ossec.conf on the AGENT is not being overwritten -- if this is correct - then yes, it is not - it won't. Only agent.conf gets pushed to the agents. ossec.conf is set manually on agents, so if you expect it to get changes - you need to use puppet or

Re: [ossec-list] Agent configuration management via central server

2012-11-28 Thread funwithossec
On Wednesday, November 28, 2012 8:45:04 AM UTC-8, Kat wrote: If I am reading your problem - you are saying ossec.conf on the AGENT is not being overwritten -- if this is correct - then yes, it is not - it won't. Only agent.conf gets pushed to the agents. ossec.conf is set manually on

[ossec-list] Re: Agent configuration management via central server

2012-11-28 Thread funwithossec
On Tuesday, November 27, 2012 4:29:54 PM UTC-8, funwithossec wrote: All, Apologies if this has been covered, but I sure couldn't find it :-) In my lab I have a central ossec 2.6 server on Ubuntu and one client on Centos, set them up with active response and followed procedure

Re: [ossec-list] Agent configuration management via central server

2012-11-28 Thread Scott Klauminzer
FYI - agent.conf extends the settings in ossec.conf. You should have a minimal set of instructions in ossec.conf, usually the server and those that will not function in agent.conf, i.e. full_command, etc. Scott On Nov 28, 2012, at 9:45 AM, funwithossec h...@donobi.net wrote: On Wednesday,