RE: [ossec-list] Re: anyone know the status of the issue where IIS logs are not able to trigger on web_rules.xml

2014-12-24 Thread James Whittington
on the IIS logs. James Whittington -Original Message- From: ossec-list@googlegroups.com [mailto:ossec-list@googlegroups.com] On Behalf Of dan (ddp) Sent: Wednesday, December 24, 2014 12:23 To: ossec-list@googlegroups.com Subject: Re: [ossec-list] Re: anyone know the status of the issue

RE: [ossec-list] Re: anyone know the status of the issue where IIS logs are not able to trigger on web_rules.xml

2014-12-24 Thread James Whittington
ed URLs (simple queries)) triggers first even though I would guess the lower rule number 31103 would be evaluated first. - in my web_rules.xml file Rule 31108 is listed before Rule 31103 so logically the positioning of the rules seems out of order (thus my questioning how rules were evaluated Ja

RE: [ossec-list] Re: anyone know the status of the issue where IIS logs are not able to trigger on web_rules.xml

2014-12-24 Thread James Whittington
simple fix and not too far reaching into the core logic of how alerts are decoded.. On Tuesday, December 23, 2014 2:24:39 PM UTC-8, James Whittington wrote: >>What does ossec-logtest respond with on the sample below? >>2014-12-12 21:00:55 W3SVC1 IIS8-5Server 1.2

RE: [ossec-list] Re: anyone know the status of the issue where IIS logs are not able to trigger on web_rules.xml

2014-12-23 Thread James Whittington
BS(CHECKSUM(NewId()))%257%20when%200%20then%20''''%2Bchar(60)%2B''div%20style=%22display:none%22''%2Bchar(62)%2B''abortion%20pill%20prescription%20''%2Bchar(60)%2B''a%20href=%22http:''%2Bchar(47)%2Bchar(47)%2BREPLACE(case%

RE: [ossec-list] Re: anyone know the status of the issue where IIS logs are not able to trigger on web_rules.xml

2014-12-22 Thread James Whittington
out there in case anything new had happened with it. James Whittington -Original Message- From: ossec-list@googlegroups.com [mailto:ossec-list@googlegroups.com] On Behalf Of Michael Starks Sent: Saturday, December 13, 2014 11:50 To: ossec-list@googlegroups.com Subject: Re: [ossec-li

RE: [ossec-list] Re: anyone know the status of the issue where IIS logs are not able to trigger on web_rules.xml

2014-12-12 Thread James Whittington
eventchannel support so I keep meaning to check that out. I will have to check out dotDefender however… James Whittington From: ossec-list@googlegroups.com [mailto:ossec-list@googlegroups.com] On Behalf Of Nathaniel Bentzinger Sent: Friday, December 12, 2014 16:45 To: ossec-list

[ossec-list] anyone know the status of the issue where IIS logs are not able to trigger on web_rules.xml

2014-12-12 Thread James Whittington
-hids/pull/434 James Whittington -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to ossec-list+unsubscr...@googlegroups.com. For more

RE: [ossec-list] I want to get rid of OSSEC's Windows GUI. What do you think?

2014-09-17 Thread James Whittington
est/manual/installation/installatio n-windows.html ) it is blank so you would need to give more guidance on how to configure the OSSEC agent. James Whittington -Original Message- From: ossec-list@googlegroups.com [mailto:ossec-list@googlegroups.com] On Behalf Of dan (ddp) Sent: Wednesday, Septembe

RE: [ossec-list] Issue triggering Active Response on Windows 2012

2014-08-01 Thread James Whittington
agent_control to restart the remote agent works and that activity is picked up my process monitor I am not quite sure where to go from here? Any ideas out there? James Whittington -Original Message----- From: James Whittington [mailto:james.whittington@gmail.com] Sent: Friday, August 0

RE: [ossec-list] Issue triggering Active Response on Windows 2012

2014-08-01 Thread James Whittington
actually passed into the AR script, WHOOPS guess I should have read the docs on creating customized AR scripts So I am going to alter my custom script to accept the expected arguments and then see of things work. James Whittington -Original Message- From: ossec-list@googlegroups.com

RE: [ossec-list] Issue triggering Active Response on Windows 2012

2014-08-01 Thread James Whittington
;m not sure where it came from I tested my custom script which is perl based and expects an ip address as input and it ran fine. If UAC is causing the issue with AR script running then I wouldn't have expected the restart-ossec.cmd to run. James Whittington -Original Message- Fr

RE: [ossec-list] Is this list working?

2014-08-01 Thread James Whittington
Okay thanks, I didn't see them in my inbox for this list but maybe that was because there are no responses to them. I forgot if google groups broadcast to all members or everyone but the poster of the comment. Anyway sorry to pester you with multiple emails. James Whittington -Ori

[ossec-list] Is this list working?

2014-08-01 Thread James Whittington
tions. You would think a google group would not block an email from google gmail? Anyhow we'll see if this message shows up or not. James Whittington -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from

[ossec-list] Issue triggering Active Response on Windows 2012

2014-08-01 Thread James Whittington
er a restart of the agent from the OSSEC server and that event does appear in a client side active response log so it appears some communication is occuring. Any ideas on how to troubleshoot why AR doesn't appear to be triggering? Thanks, James Whittington -- --- You received

[ossec-list] Issue triggering Active Response on Windows 2012

2014-07-31 Thread James Whittington
rt of the agent from the OSSEC server and that event does appear in a client side active response log so it appears some communication is occuring. Any ideas on how to troubleshoot why AR doesn't appear to be triggering? Thanks, James Whittington -- --- You received this message because you a

Re: [ossec-list] Decoder for IIS 7 Logs

2014-07-30 Thread James Whittington
ocal_decoder.xml etc/decoder.xml However I am pretty sure on our production instance we don't specifically define local_decoder.xml so I think OSSEC must discover it if it's in the "./ossec/etc" folder Thanks again for the help. James Whittington On Wed, Jul 30, 2014 at 10:55 AM, dan

Re: [ossec-list] Decoder for IIS 7 Logs

2014-07-30 Thread James Whittington
cents. On Wed, Jul 30, 2014 at 11:40 AM, dan (ddp) wrote: > On Wed, Jul 30, 2014 at 11:31 AM, James Whittington > wrote: > > Dan, thanks for taking a quick look at the log line. > > I'll try to modify the iis6 decoder and see what happens then. > > I have a OSSEC te

Re: [ossec-list] Decoder for IIS 7 Logs

2014-07-30 Thread James Whittington
ilize OSSEC that they would share if there were a place for them to do so. James Whittington On Wed, Jul 30, 2014 at 11:00 AM, dan (ddp) wrote: > On Wed, Jul 30, 2014 at 10:55 AM, dan (ddp) wrote: > > On Wed, Jul 30, 2014 at 10:28 AM, James Whittington > > wrote: > >>

[ossec-list] Decoder for IIS 7 Logs

2014-07-30 Thread James Whittington
k registration activity to a web service and trigger a custom AR script if multiple registration attempts occur from the same source ip. If anyone would like to share their IIS decoders I would be most appreciative, I don't know why OSSEC doesn't have a user contributed exchange of decode

RE: [ossec-list] Re: How does OSSEC keep track of what events it has not processed?

2014-03-17 Thread James Whittington
you may want to try an alternative approach I used for testing. You can leave the OSSEC agent running, but simply use a separate process to pull IIS logs from Azure and append it line by line to the monitored local file. On Tuesday, March 4, 2014 6:58:16 AM UTC-8, James Whittington wrote: How

[ossec-list] How does OSSEC keep track of what events it has not processed?

2014-03-04 Thread James Whittington
applications we have in the cloud. Thanks, James Whittington -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to ossec-list+unsubscr...@googlegroup

[ossec-list] Is it still true that for IIS logfile format the logs have to be set to daily

2014-03-03 Thread James Whittington
asn't sure how OSSEC would react to that event either? Thanks. James Whittington -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to

RE: [ossec-list] Unable to Audit Print Jobs with Windows Agent

2014-02-06 Thread James Whittington
t viewer) I do see a reference to Channel Microsoft-Windows-TaskScheduler/Operational . So maybe I am asking if OSSEC can read Event Channels in Windows and if so what would the syntax of that look like? James Whittington -Original Message- From: ossec-list@googlegroups.com [mailto:ossec-list@

RE: [ossec-list] Unable to Audit Print Jobs with Windows Agent

2014-02-06 Thread James Whittington
t signal. Can the OSSEC Windows Agent handle eventlogs listed under Applications and Service Logs Area of the Windows Event Viewer? If so would the log_format be eventlog ? Thanks, James Whittington From: ossec-list@googlegroups.com [mailto:ossec-list@googlegroups.com] On Beh

RE: [ossec-list] Re: Option to include a file of local directory definitions on a Windows client

2013-08-27 Thread James Whittington
bout using the agent.conf option to push config files out to the remote agents it would seem allowing the use of an external file for local customizations would make a lot of sense. James Whittington From: ossec-list@googlegroups.com [mailto:ossec-list@googlegroups.com] On Behalf O

RE: [ossec-list] Option to include a file of local directory definitions on a Windows client

2013-08-27 Thread James Whittington
ct it into the correct place in the OSSEC config file. James Whittington james.whitting...@vc3.com -Original Message- From: ossec-list@googlegroups.com [mailto:ossec-list@googlegroups.com] On Behalf Of Devon J. Greene Sent: Monday, August 26, 2013 11:35 PM To: ossec-list@googlegroup

[ossec-list] Option to include a file of local directory definitions on a Windows client

2013-08-26 Thread James Whittington
the main config file. I am hoping I just missed this option as it sounds like something that could be in the agent.conf file and pushed out to multiple servers. James Whittington -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To u

RE: [ossec-list] OSSEC manager for Windows?

2013-03-21 Thread James Whittington
Host Intrusion Detection was needed I would be looking toward a Windows based HID, I pretty sure McAfee makes one. James Whittington From: ossec-list@googlegroups.com [mailto:ossec-list@googlegroups.com] On Behalf Of René Kåbis Sent: Wednesday, March 20, 2013 3:18 PM To: ossec-list

RE: [ossec-list] Large ruleset causing ossec startup issues?

2013-02-19 Thread James Whittington
run ossec-makelists to rebuild the lists, does that require a manual restart of ossec-analysisd? Thanks, James Whittington -Original Message- From: ossec-list@googlegroups.com [mailto:ossec-list@googlegroups.com] On Behalf Of dan (ddp) Sent: Tuesday, February 19, 2013 9:55 AM To: ossec-l

RE: [ossec-list] Re: Having Issues Getting geoip working on beta 2

2012-10-31 Thread James Whittington
[enabled by default] ar cru alerts.a mail.o log.o exec.o getloglocation.o ranlib alerts.a If I have time I may just try building on another server to see if I can reproduce the condition or hopefully just get the binaries (with geoip support) built. James Whittington

RE: [ossec-list] Re: Having Issues Getting geoip working on beta 2

2012-10-30 Thread James Whittington
ere? Anyone else working with ossec beta + geoip + Ubuntu out there?? James Whittington From: ossec-list@googlegroups.com [mailto:ossec-list@googlegroups.com] On Behalf Of Jb Cheng Sent: Monday, October 29, 2012 7:30 PM To: ossec-list@googlegroups.com Subject: [ossec-list] Re: Having Issues

[ossec-list] Having Issues Getting geoip working on beta 2

2012-10-25 Thread James Whittington
-rwxr-xr-x 1 root root71255 Oct 22 13:14 libGeoIPUpdate.so.0.0.0 Has anyone else had or worked around these issues ? I would really like to get the geoip stuff working.. Thanks.. James Whittington

RE: [ossec-list] What is the best way to test rules on Windows Event Logs?

2012-10-22 Thread James Whittington
Thanks to everyone for the advice on testing eventlog rules. Unfortunately my ossec server is the EC2 Amazon Cloud right now and they are having major issues on the Northeast US datacenter :<(.. Thank goodness my production stuff is elsewhere :<).. James Whittington -Original M

[ossec-list] What is the best way to test rules on Windows Event Logs?

2012-10-22 Thread James Whittington
event in windows? Thanks, James Whittington

RE: [ossec-list] msauth_rules.xml question

2012-10-22 Thread James Whittington
will go ahead and make the jump to the beta. I have some linux based systems but much of my web services stuff is windows 2008, 2008 r2 and now Windows 2012. So if I am going to spend time tuning I guess I should start from the latest code. James Whittington -Original Message- From: ossec

RE: [ossec-list] msauth_rules.xml question

2012-10-19 Thread James Whittington
pe 10|Type: 10|Logon Type: 10 Remote access login failure. authentication_failed, 18107 Type 10|Type: 10|Logon Type: 10 Remote access login success. authentication_success, James Whittington From: ossec-list@googlegroups.com [mailto:ossec-l

[ossec-list] Active Response Questions

2012-10-03 Thread James Whittington
P's in the local_rules.xml file on the OSSEC server? Currently OSSEC is generating a good bit of noise but I am also now blocking attacks I previously didn't know about so I am determined to tune it as I learn how to better use it. James Whittington