RE: [ossec-list] Re: Concern about the ossec-csyslogd daemon

2012-01-10 Thread Bruno Plantier
la part de dan (ddp) Envoyé : lundi 9 janvier 2012 16:21 À : ossec-list@googlegroups.com Objet : Re: [ossec-list] Re: Concern about the ossec-csyslogd daemon OSSEC version? Platform? Configuration? On Mon, Jan 9, 2012 at 8:18 AM, Bruno Plantier bruno.plant...@lyra-network.com wrote: Hello folks

RE: [ossec-list] Re: Concern about the ossec-csyslogd daemon

2012-01-09 Thread Bruno Plantier
Hello folks. I'm facing the same problem with ossec-csyslogd daemon. Every time I start the process, it crashes after a few minutes. I've tried to get some gdb traces as asked and here is what I get: Starting program: /var/ossec/bin/ossec-csyslogd warning: no loadable sections found in added

[ossec-list] custom Decoder or Rule matching log filename.

2010-01-27 Thread Bruno PLANTIER
Hi everybody. Is there a way to create a custom Decoder (or Rule) that matches the name of the initial monitor log filename? For exemple: * I have an Ossec client that monitors a file /usr/local/jboss/server/ default/log/server.log configured as syslog file. localfile