Re: [ossec-list] OSSEC install on Solaris 9

2017-06-30 Thread Mathew Habicht
We were able to modify the source code to get the install for Solaris 9 to work. On Monday, June 26, 2017 at 3:35:45 PM UTC-4, Eero Volotinen wrote: > > so, you are using sun compiler instead of gcc.. just fix that issue.. > > 26.6.2017 10.32 ip. "Mathew Habicht" > > kirjoitti: > >> # gcc --vers

[ossec-list] 2.9.1 Max Agents

2017-06-30 Thread Eduardo Nunez
Trying to change the max agents in version 2.9.1, but the make command used in previous version does not work. Is the default agent limit the same or has that been changed? And is it still changeable? -- --- You received this message because you are subscribed to the Google Groups "ossec-li

Re: [ossec-list] 2.9.1 Max Agents

2017-06-30 Thread dan (ddp)
On Thu, Jun 29, 2017 at 5:17 PM, Eduardo Nunez wrote: > Trying to change the max agents in version 2.9.1, but the make command used > in previous version does not work. Is the default agent limit the same or > has that been changed? And is it still changeable? > I think the default limit is the s

Re: [ossec-list] Solaris 10 install issue - Fatal error in reader: Makefile, line 4

2017-06-30 Thread dan (ddp)
On Thu, Jun 29, 2017 at 8:40 PM, Patrick Tobin wrote: > Not sure if this will help but these are the steps I took to build a binary > installer for Solaris 10 (I did the same for 2.8.3 and it worked as well): > > > > Compile OSSEC on Solaris 10 with OPENSSL Support > > > > 1. Install opencsw pkg

Re: [ossec-list] Integration with MS SCCM

2017-06-30 Thread dan (ddp)
On Thu, Jun 29, 2017 at 1:00 AM, Irshad Rahimbux wrote: > Dear Team, > > I would like to integrate Microsoft SCCM with OSSIM. > > All configuration has been done in ms-sccm.cfg [which was already > available]. > > Logs are coming to /var/log/alienvault/agent.log but not to > /var/ossec/logs/alerts

Re: [ossec-list] OSSEC Active Response Block on pattern-matched SSH user logins

2017-06-30 Thread dan (ddp)
On Thu, Jun 29, 2017 at 4:08 AM, Rahul Tiwari wrote: > > > 0down votefavorite > > I need to block the user ip after 3 times login failed attempt in ossec I > tried below in sshd_rules file > > > 5716 > > Multiple SSHD authentication failures. > authentication_failures, > > >