Re: [ossec-list] Re: Watchguard Firebox logs

2015-10-27 Thread dan (ddp)
On Oct 27, 2015 4:49 AM, "Tero Onttonen" wrote: > > Hi, > > I would be interested in to find a solution regarding Watchguard logs. I did not find a solution after some searching. > > Did this go any further? > Are the logs the same as they were in 2009? > Br, > Tero > > On Wednesday, March 11, 2

Re: [ossec-list] Re: Watchguard Firebox logs

2015-10-27 Thread Eero Volotinen
Did you checked out watchguard dimension appliance? Eero 27.10.2015 10.49 ap. "Tero Onttonen" kirjoitti: > Hi, > > I would be interested in to find a solution regarding Watchguard logs. I > did not find a solution after some searching. > > Did this go any further? > > Br, > Tero > > On Wednesday

[ossec-list] Re: Watchguard Firebox logs

2015-10-27 Thread Tero Onttonen
Hi, I would be interested in to find a solution regarding Watchguard logs. I did not find a solution after some searching. Did this go any further? Br, Tero On Wednesday, March 11, 2009 at 2:11:44 PM UTC+2, rob.but...@gmail.com wrote: > > Thanks. I'm also working AQTRONIX WebKnight logs too.

[ossec-list] Re: Watchguard Firebox logs

2009-03-11 Thread rob . butterworth
Thanks. I'm also working AQTRONIX WebKnight logs too. Here's a few watchguard examples. I've blanked a few bits of info. Note that we've adopted a convention of putting wg_ at the start of the system name so we can identify them as watchguard logs, but perhaps this isn't the best way ? 2009 M

[ossec-list] Re: Watchguard Firebox logs

2009-03-10 Thread Daniel Cid
Hi Rob, I don't think anyone did this yet. Can you share some of your logs with us? We can certainly help writing some rules/decoders if we get some samples... Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On Mon, Mar 2, 2009 at 10:47 AM, wrote: > > Hi, > Has anyone got OSSEC to parse Watc

[ossec-list] Re: Watchguard Firebox logs

2009-03-09 Thread rrodgers
I would be interested in this as well. Robert On Mar 2, 9:47 am, rob.butterwo...@gmail.com wrote: > Hi, > Has anyone got OSSEC to parse WatchguardFireboxlogs ?  I have my > logs coming in via syslog, and being stored, but if I run them through > logtest they get recognized as Debian dpkg logs, s