[ossec-list] Re: OSSEC HIDS rules help please

2015-01-21 Thread Fred974
re: smtp-out: Connecting to tls://IPv6 Thank you very much. hope this is clearer Fred On Wednesday, 21 January 2015 11:02:40 UTC, Fred974 wrote: > > Hello, > > I keep getting the following email notification from the ossec server. > > OSSEC HIDS Notification. 2015 Jan 12 06:

[ossec-list] OSSEC HIDS rules help please

2015-01-21 Thread Fred974
Hello, I keep getting the following email notification from the ossec server. OSSEC HIDS Notification. 2015 Jan 12 06:00:01 Received From: trinity->/var/log/maillog Rule: 1002 fired (level 2) -> "Unknown problem somewhere in the system." Portion of the log(s): Jan 12 06:00:00 trinity smtpd[116

[ossec-list] Re: Unknown problem somewhere in the system

2015-01-09 Thread Fred974
Thank You very much Dan, I will test the solution and change it if it doesn't work. Great staring point :) Fred On Friday, 2 January 2015 13:49:28 UTC, Fred974 wrote: > > Hi, > > I keep receiving an email with the following content: > > OSSEC HIDS Notification.

[ossec-list] Re: Unknown problem somewhere in the system

2015-01-06 Thread Fred974
for my need? 31101 1002 do not send by email Thank you F Hi Dan, Is there any chances, you could give me simple example please? On Friday, 2 January 2015 13:49:28 UTC, Fred974 wrote: > > Hi, > > I keep receiving an email with the follo

[ossec-list] Unknown problem somewhere in the system

2015-01-02 Thread Fred974
Hi, I keep receiving an email with the following content: OSSEC HIDS Notification. > 2015 Jan 02 12:00:01 > > Received From: trinity->/var/log/maillog > Rule: 1002 fired (level 2) -> "Unknown problem somewhere in the system." > Portion of the log(s): > > Jan 2 12:00:00 trinity smtpd[1161]: smtp-

[ossec-list] Re: AnaLogi - OSSEC WUI v1.3

2014-12-29 Thread Fred974
t;.$sqlmodule." Test 2 - Can PHP connect to your MySQL? - ".$mysqlconnect. " Test 3 - Does your database have correct schema? - ". $databaseschema." Test 4 - Is there any data in your database? - ".$anydata. ""; } The problem that I

[ossec-list] Re: AnaLogi - OSSEC WUI v1.3

2014-12-29 Thread Fred974
UTC, Fred974 wrote: > > Hi, > > I have successfully installed ossec on my server but when accessing the > AnaLogi web interface, I get the following message: > > > *Test 4 - Is there any data in your database? - no! Fix - Ensure > agents are logging data.* >

[ossec-list] Re: AnaLogi - OSSEC WUI v1.3

2014-12-29 Thread Fred974
rows in set (0.00 sec) I can see that I have data in some tables but not all of them. I'm not sure why Fred On Monday, 29 December 2014 14:15:10 UTC, Fred974 wrote: > > Hi, > > I have successfully installed ossec on my server but when accessing the > AnaLogi web interface,

[ossec-list] AnaLogi - OSSEC WUI v1.3

2014-12-29 Thread Fred974
Hi, I have successfully installed ossec on my server but when accessing the AnaLogi web interface, I get the following message: *Test 4 - Is there any data in your database? - no! Fix - Ensure agents are logging data.* Could someone please help me in solving this issue. >From another

[ossec-list] Re: ossec-wui installation problem

2014-12-29 Thread Fred974
Sorry one more question.. Does it need to have read-write access or would read-only suffice? On Monday, 29 December 2014 10:24:07 UTC, Fred974 wrote: > > Hello, > > My web server and the ossec server are on 2 different machines. > > When trying to setup the ossec web interface o

[ossec-list] Re: ossec-wui installation problem

2014-12-29 Thread Fred974
So it has to be installed on the same server? On Monday, 29 December 2014 10:24:07 UTC, Fred974 wrote: > > Hello, > > My web server and the ossec server are on 2 different machines. > > When trying to setup the ossec web interface on my web server by running > the ./setup.sh

[ossec-list] ossec-wui installation problem

2014-12-29 Thread Fred974
Hello, My web server and the ossec server are on 2 different machines. When trying to setup the ossec web interface on my web server by running the ./setup.sh, it asked me for the 'OSSEC install directory path' As the ossec install is not local to the machine, how do I tell it to look on the r

[ossec-list] Re: Data not been logged to MySQL

2014-12-29 Thread Fred974
Ok thank you On Friday, 19 December 2014 16:06:16 UTC, Fred974 wrote: > > Hello, > > I I have set ossec to output the data to MySQL but I have no data in it.. > After doing a few digging on the server, I realized that I had the > following in my mysql-slow.log file: > Tcp po

[ossec-list] Re: Data not been logged to MySQL

2014-12-29 Thread Fred974
Hi Dan, I am sorry but I do not understand your reply. Could you please rephrase? Thank you Fred On Friday, 19 December 2014 16:06:16 UTC, Fred974 wrote: > > Hello, > > I I have set ossec to output the data to MySQL but I have no data in it.. > After doing a few digging o

[ossec-list] Re: Data not been logged to MySQL

2014-12-19 Thread Fred974
for ossec agent and server are clean... On Friday, 19 December 2014 16:06:16 UTC, Fred974 wrote: > > Hello, > > I I have set ossec to output the data to MySQL but I have no data in it.. > After doing a few digging on the server, I realized that I had the > following in my mysql-slow.l

[ossec-list] Data not been logged to MySQL

2014-12-19 Thread Fred974
Hello, I I have set ossec to output the data to MySQL but I have no data in it.. After doing a few digging on the server, I realized that I had the following in my mysql-slow.log file: Tcp port: 2596 Unix socket: /tmp/mysql.sock Time Id CommandArgument # Time: 141219 15:33:03

[ossec-list] Re: FreeBSD - Agent not working

2014-12-16 Thread Fred974
at is the ossec-syscheckd(1224): ERROR: Error sending message to queue.? Thank you Fred On Tuesday, 2 December 2014 13:47:36 UTC, Fred974 wrote: > > Hi Guys, > > This is my first post on here... > > I have recently installed ossec-hids on FreeBSD and looking at the agent

[ossec-list] Re: FreeBSD - Agent not working

2014-12-15 Thread Fred974
day, 2 December 2014 13:47:36 UTC, Fred974 wrote: > > Hi Guys, > > This is my first post on here... > > I have recently installed ossec-hids on FreeBSD and looking at the agent > log, I get the following errormessage: > > 2014/12/01 13:37:41 ossec-syscheckd: socket busy

[ossec-list] Re: FreeBSD - Agent not working

2014-12-15 Thread Fred974
Fred On Tuesday, 2 December 2014 13:47:36 UTC, Fred974 wrote: > > Hi Guys, > > This is my first post on here... > > I have recently installed ossec-hids on FreeBSD and looking at the agent > log, I get the following errormessage: > > 2014/12/01 13:37:41 ossec-syscheckd:

[ossec-list] Re: FreeBSD - Agent not working

2014-12-02 Thread Fred974
ossec-jail-problem.49228/#post-275393 Hope you can help. Thank you On Tuesday, 2 December 2014 13:47:36 UTC, Fred974 wrote: > > Hi Guys, > > This is my first post on here... > > I have recently installed ossec-hids on FreeBSD and looking at the agent > log, I get the following err

[ossec-list] FreeBSD - Agent not working

2014-12-02 Thread Fred974
Hi Guys, This is my first post on here... I have recently installed ossec-hids on FreeBSD and looking at the agent log, I get the following errormessage: 2014/12/01 13:37:41 ossec-syscheckd: socket busy .. 2014/12/01 13:37:42 ossec-logcollector: socket busy .. 2014/12/01 13:37:51 ossec-syschec