Will do, thank you!
On Tue, Feb 2, 2016 at 7:10 PM, Antonio Querubin wrote:
> On Tue, 2 Feb 2016, Santiago Bassett wrote:
>
> From src/headers/defs.h, here are some interesting constants
>>
>> #define OS_MAXSTR OS_SIZE_6144/* Size for logs, sockets, etc */
>>
>> #define OS_BUFFER_SIZE
On Tue, 2 Feb 2016, Santiago Bassett wrote:
From src/headers/defs.h, here are some interesting constants
#define OS_MAXSTR OS_SIZE_6144/* Size for logs, sockets, etc */
#define OS_BUFFER_SIZE OS_SIZE_2048/* Size of general buffers */
#define OS_FLSIZE OS_SIZE_256
>From src/headers/defs.h, here are some interesting constants
#define OS_MAXSTR OS_SIZE_6144/* Size for logs, sockets, etc */
#define OS_BUFFER_SIZE OS_SIZE_2048/* Size of general buffers */
#define OS_FLSIZE OS_SIZE_256 /* Maximum file size*/
#define
How big are those logs, do you have an example?
This kind of behavior has been reported several times in the last few days
(for different use cases). Haven't had time to look into it but I assume is
a limitation in the alert size. Have you tried using logall option? Do you
see the complete event i
Hi,
I have an OSSEC Server receiving IIS logs from several servers via agent
configuration:
ex:
* PATH/W3SVCx/u_ex%y%m%d%H.log
iis *
Everything works like a charm. However, some of my IIS logs are longer than
usual (more than 1256 chars long). When this happens, Alerts are equally