Re: [ossec-list] ossec server 2.9.0 WinEvt problems

2017-02-10 Thread dan (ddp)
On Feb 10, 2017 8:13 AM, "Chris Snyder" wrote: My only counter argument to your response is that if I do the same tests with a 2.8.3 ossec server all the tests pass with the expected match of a windows log type. So something changed somewhere in the ossec server. Whether this is a new bug recent

Re: [ossec-list] ossec server 2.9.0 WinEvt problems

2017-02-10 Thread Chris Snyder
My only counter argument to your response is that if I do the same tests with a 2.8.3 ossec server all the tests pass with the expected match of a windows log type. So something changed somewhere in the ossec server. Whether this is a new bug recently introduced between 2.8.3 and 2.9.0 or it

Re: [ossec-list] Debugging Unprocessed Log Entries

2017-02-10 Thread Quintin Beukes
Thanks Dan. Is there a way to get OSSEC to provide more details on the messages it actually processes? I'd like to gain a better understanding of this application because it has a lot of seemingly random behaviour. On Thursday, February 9, 2017 at 9:59:24 PM UTC+2, dan (ddpbsd) wrote: > > On Thu