Re: [ossec-list] Client.keys

2013-09-23 Thread Jared
Okay, off line then via email. Jared On Friday, September 20, 2013 9:48:10 AM UTC-4, Chris Lauritzen wrote: > > Jared, > > What I am trying to do it automate the install. We use LANDesk to push out > apps to over 3500 PC/servers in our company. LANDesk can use batch, msi, > exe, vbs and Powers

Re: [ossec-list] Client.keys

2013-09-23 Thread Chris Lauritzen
Michael, That sounds like an option. I'm looking at it now. On Friday, September 20, 2013 9:55:19 AM UTC-5, Michael Starks wrote: > > On 09/20/2013 08:48 AM, Chris Lauritzen wrote: > > So what I am looking to do is to find a way > > to not create 3500 Client.keys files. > > You could create a

Re: [ossec-list] troubles with windows logs collecting

2013-09-23 Thread dan (ddp)
On Fri, Sep 20, 2013 at 8:05 AM, Vasya Gorbachev wrote: > now i did it another way > > wrote the decoder > > ^\d\d\d\d \w+ \d\d \d\d:\d\d:\d\d \(\w+\) 0\.0\.0\.0->WinEvtLog > WinEvtLog: Kaspersky Event Log: > > Logs in archives.log get a header prepended to them. The log message you actually

[ossec-list] Syscheckd inotify limit

2013-09-23 Thread Franz Nemeth
Hello, We recently encoutered a problem with the syscheck daemon and inotify: We are monitoring quite a large number of files in realtime and the inotify_user_watches is still set on 8192 files. This resulted in several commands not working anymore (tailf for instance). Is there a way to limit

[ossec-list] Re: OSSEC integration into Alienvault SIEM webinar

2013-09-23 Thread Chris H
Hi Santiago. I was doing a bit of research into this exact topic myself already, so perfect timing :) I've registered, but do you know if the presentation/video will be made available afterwards, in case I am unable to attend? Thanks, Chris On Saturday, September 21, 2013 2:06:22 AM UTC+1, Sa