[ossec-list] RE: manage_agent fails again

2014-11-26 Thread Chris Tweed
ways around obstacles. I’ll let you know how I get on with that “manage_agents –i” when I get a chance to try ☺ Chris -- Chris Tweed From: ossec-list@googlegroups.com [mailto:ossec-list@googlegroups.com] On Behalf Of Colin Bruce Sent: 26 November 2014 14:08 To: ossec-list@googlegroups.com

[ossec-list] RE: manage_agent fails again

2014-11-26 Thread Chris Tweed
ris -- Chris Tweed From: ossec-list@googlegroups.com [mailto:ossec-list@googlegroups.com] On Behalf Of Colin Bruce Sent: 25 November 2014 17:17 To: ossec-list@googlegroups.com Subject: [ossec-list] manage_agent fails again Is there any way on Windows to install the agent’s key without using the GUI

[ossec-list] RE: list_agents -n shows non-existing clients?

2014-11-11 Thread Chris Tweed
pgrade now that I have got to the bottom of the issue). Regards, Chris -- Chris Tweed Technical Support Shoe Zone T: 0116 2223000 W: www.shoezone.com -Original Message- From: ossec-list@googlegroups.com [mailto:ossec-list@googlegroups.com] On Behalf Of Chris Tweed Sent: 06 Novem

[ossec-list] list_agents -n shows non-existing clients?

2014-11-06 Thread Chris Tweed
n so be it. We have a single OSSEC server running under Ubuntu server 12.04.5 LTS 64 bit (as a Hyper-V virtual machine). Thank you, Chris -- Chris Tweed Please consider the environment before printing this email CONFIDENTIALITY NOTICE This E-Mail contains information which is confidential and

Re: [ossec-list] Re: Preventing rule 18152 from firing if failed login attempt is from a certain server

2011-01-07 Thread Chris Tweed
://www.ossec.net/wiki/Know_How:Multiple_Failures_WindowsAD > > > On 01/06/2011 09:19 AM, Chris Tweed wrote: > > I believe I have now managed to solve my rule 18152 issue with the > following rule. I was getting events generated every 30 mins and I've now > not had any for the last 3 hours. > >

[ossec-list] Re: Preventing rule 18152 from firing if failed login attempt is from a certain server

2011-01-06 Thread Chris Tweed
dy spots a fatal flaw in what I've done :^) 10 SERVER-NAME 18152 Ignoring SERVER-NAME On 5 January 2011 09:37, Chris Tweed wrote: > This is my first posting to this list having rolled OSSEC HIDS out to an > estate of around 800 Windows based machines towards the end of l

[ossec-list] Preventing rule 18152 from firing if failed login attempt is from a certain server

2011-01-05 Thread Chris Tweed
This is my first posting to this list having rolled OSSEC HIDS out to an estate of around 800 Windows based machines towards the end of last year as part of our PCI compliance strategy. Everything is running very smoothly and I just have one niggle, rule 18152. I have made a few other simple rule