Re: [ossec-list] Monitor Particular Folder On Windows Agent

2017-07-19 Thread Akash Munjal
Hi Dan, If i add or delete file in a particular folder on windows agent desktop. I want to see their addition or deletion log on server/manager side. -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop

[ossec-list] Monitor Particular Folder On Windows Agent

2017-07-19 Thread Akash Munjal
Hi All, Can I monitor a particular folder on desktop of my windows agent. If yes then how it can be done. Also I want to monitor a particular drive(:C). thanks... -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this g

[ossec-list] Re: No Decoder Match Problem

2017-06-12 Thread Akash Munjal
thanks dan & Jesus Linares for your help -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to ossec-list+unsubscr...@googlegroups.com. For more options, visi

[ossec-list] No Decoder Match Problem

2017-06-09 Thread Akash Munjal
Hi, I create custom decoder, /var/ossec/etc/local_decoder.xml as: myapplication ^myapplication: Entry of decoder in manager ossec.conf file as: local_rules.xml etc/decoder.xml etc/local_decoder.xml rules/plugins when i run logtest command it show this: /var/osse

[ossec-list] How ossec manager reads decoder

2017-06-08 Thread Akash Munjal
HI, How ossec manager reads decoder...? Thanks.. -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to ossec-list+unsubscr...@googlegroups.com. For more opti

[ossec-list] Don't Getting Alerts From Window Agent to Linux Manager

2017-05-31 Thread Akash Munjal
Hi All, I am also facing the same problem.I am not getting alert of creation/deletion of file from windows agent to my manager(linux). Agent show connected and active, I only get alert from agent(win) is agent start/restart/change in ossec.conf(agent). To monitor D:\ drive, I have done the fo

[ossec-list] Re: OSSEC - windows event

2017-05-30 Thread Akash Munjal
Hi All, I am also facing the same problem.I am not getting alert of creation/deletion of file from windows agent to my manager(linux). Agent show connected and active, I only get alert from agent(win) is agent start/restart/change in ossec.conf(agent). To monitor D:\ drive, I have done the fo

[ossec-list] Ossec with ELK

2017-05-18 Thread Akash Munjal
Hi All, Anyone can help me in configuring oseec with ELK stack. I don't know how to do it. Thank's -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to os

Re: [ossec-list] Unable to connect with agent

2017-05-17 Thread Akash Munjal
Thanks Pedro, really appreciable. -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to ossec-list+unsubscr...@googlegroups.com. For more options, visit https://gr

Re: [ossec-list] Unable to connect with agent

2017-05-16 Thread Akash Munjal
Hi Dan, I want know, how ossec manager found that agent is disconnected. Not by " /var/ossec/bin/agent_control -lc " this command. I mean by their connection(or communication). -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe

Re: [ossec-list] Unable to connect with agent

2017-05-16 Thread Akash Munjal
Hi Dan Problem has been resolved now. Thanks for your help. On Saturday, May 13, 2017 at 5:23:49 AM UTC+5:30, dan (ddpbsd) wrote: > > On Fri, May 12, 2017 at 4:45 AM, Akash Munjal > wrote: > > Hi dan, > > > > Thanks for the response. I tried this, but problem rem

Re: [ossec-list] Unable to connect with agent

2017-05-12 Thread Akash Munjal
Hi dan, Thanks for the response. I tried this, but problem remains same. If you have another method to solve this please share. Best Regards, Akashdeep Munjal -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group a

[ossec-list] Unable to connect with agent

2017-05-11 Thread Akash Munjal
Hi All, I can not receive alert from this agent(ID:1024). When i check the status it look like this. Please help me out. /var/ossec/bin/agent_control -i 1024 OSSEC HIDS agent_control. Agent information: Agent ID: 1024 Agent Name: MMTC_UAT_APP1_X.X.X.X IP address: any/any Statu