[ossec-list] OSSEC /HIDS literature...

2014-05-20 Thread rockandsnap
ehlo everyone, I'm planning on writing my bachelor thesis on OSSEC and HIDS. Since i'm in the early phase of researching, I'm currently looking for good literature that I could base my thesis on. So far I've only found these two books, which I'm probably gonna order asap. OSSEC Host-Based

Re: [ossec-list] deploying ossec-agents with puppet

2013-11-27 Thread rockandsnap
thanks for the explanation and for the manifest, Stephane! yes, i have an ossec user with the uid 5, so I will adapt this now. at the moment i only have one ossec server, but there may be another one at some point. so for now I will change this to $ossec_server = hostname of the ossec

[ossec-list] deploying ossec-agents with puppet

2013-11-26 Thread rockandsnap
hi there, i know this question has probably been asked a hundred times beforei've also done some digging in our beloved ossec google groups, but haven't found the right answer yet. i want to deploy the ossec-agents with puppet, and therefore i'd need a puppet manifest. i have already

[ossec-list] Re: ossec con in europe?!

2013-11-20 Thread rockandsnap
*Great, can anyone help spread the word for this? *the more people involved the better! I'd be most interested in such a conference!!! I even would be willing to organize (or help organize) such an event, since I can't afford travelling so far (time-issues). So please let me know about the

[ossec-list] Re: ossec con in europe?!

2013-10-25 Thread rockandsnap
wonderful, thanks for your positive feedback Jb Cheng! :) i'd be most interested, is there any way to spread the news? i haven't checked IRC yet, are there many europeans hanging out there? maybe this question can also be posted on the OSSEC website or through Daniel's blog? what other major

[ossec-list] ossec con in europe?!

2013-10-24 Thread rockandsnap
hi there, i know recently there was an ossec conference in the US last summeri was wondering if there is any interest/demand for something similar in europe. how many european people use ossec? unfortunately i don't have the opportunity to travel so far for one-day events :( so something

Re: [ossec-list] Re: Server Install With Db Support

2013-10-23 Thread rockandsnap
Hmm, unfortunately it didn't work. I still get this error: *** Making os_dbd *** make[1]: Entering directory `/home/theresa/ossec-hids-2.7/src/os_dbd' Compiling DB support with: gcc -g -Wall -I../ -I../headers -DDEFAULTDIR=\/var/ossec\ -DUSE_OPENSSL -DUSEINOTIFY -DARGV0=\ossec-dbd\

Re: [ossec-list] Re: Server Install With Db Support

2013-10-23 Thread rockandsnap
good news: I've fixed it myself. apparently the library mysql-devel was missing. now it installed correctly and i finally get: OSSEC HIDS v2.7 - Trend Micro Inc. Compiled with MySQL support. :) On Tuesday, March 20, 2012 11:29:05 PM UTC+1, Joshua Albright wrote: Hi, Has a fix or workaround

[ossec-list] Re: AnaLogi - OSSEC WUI

2013-10-22 Thread rockandsnap
Hi, first of all let me thank you for this great idea. it seems like a good way to display the results found by ossec. at the moment i still have problems setting up analogi. while the first two tests went OK, the 3rd and 4th test failed. Test 1 - Can PHP detect MySQL module? - yes Test 2 -

[ossec-list] Re: AnaLogi - OSSEC WUI v1.2

2013-10-22 Thread rockandsnap
Hi, I currently have a problem setting up analogi. During the installation i get the following error: Test 1 - Can PHP detect MySQL module? - yes Test 2 - Can PHP connect to your MySQL? - yes *Test 3 - Does your database have correct schema? - no! Fix - Import the MySQL schema that comes

Re: [ossec-list] Re: Server Install With Db Support

2013-10-22 Thread rockandsnap
Hi, I get the following error, when I re-compile ossec-hids with the modified Makefile *** Making os_dbd *** make[1]: Entering directory `/home/theresa/ossec-hids-2.7/src/os_dbd' Compiling DB support with: gcc -g -Wall -I../ -I../headers -DDEFAULTDIR=\/var/ossec\ -DUSE_OPENSSL

Re: [ossec-list] Re: Server Install With Db Support

2013-10-22 Thread rockandsnap
Hi Dan, thanks for getting back to me. I'm using Fedora 18 (as my test environment) and will use RHEL 6.4 on my production environment. So far I've only tested the re-compile on my test environment. I'm using the latest stable version which is 2.7 The modification I made in the Makefile (in

Re: [ossec-list] Re: Server Install With Db Support

2013-10-22 Thread rockandsnap
This is exactly what I did, after editing the makefile cd src make setdb cd .. ./install.sh -- --- You received this message because you are subscribed to the Google Groups ossec-list group. To unsubscribe from this group and stop receiving emails from it, send an email to

Re: [ossec-list] Re: Server Install With Db Support

2013-10-22 Thread rockandsnap
Ok, will do it tomorrow. But I thought the modifications in the makefile enabled the mysql support?! -- --- You received this message because you are subscribed to the Google Groups ossec-list group. To unsubscribe from this group and stop receiving emails from it, send an email to