[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[ossec-list] Re: "Invalid hostname in syslog message:"




Hi Rafael,

*Please use English in our list, since most of the users do not speak
portuguese.

The issue here is that ossec is trying to parse "UDP:" as the hostname and
not being able to do so (":" is not valid in the hostname). This is happening
because this log is not in a proper syslog format. Btw, where is this
log coming from?

Thanks,

--
Daniel B. Cid
dcid ( at ) ossec.net

On 5/3/07, Rafael Busetti <omegatiger@xxxxxxxxx> wrote:

Boa tarde,

   Estou tendo problemas no meu Freebsd 6.2 com o ossec, na parte de
logs ele lança vários logs dando esses erros...

12:42:34 ossec-analysisd(1275): Invalid hostname in syslog message:
'May  3 12:42:33 UDP: dgram to port 54177 from 201.10.4.3:53 (62 data
bytes)'.
 12:42:34 ossec-analysisd(1275): Invalid hostname in syslog message:
'May  3 12:42:34 UDP: dgram to port 52168 from 71.178.215.112:8065 (29
data bytes)'.
 12:42:58 ossec-analysisd(1275): Invalid hostname in syslog message:
'May  3 12:42:56 TCP: port 2967 connection attempt from
200.203.18.72:3628'.

eu preciso mudar algo antes de compilar os sources do programa?

Obrigado!



OSSEC home | Main Index | Thread Index


OSSEC project: www.ossec.net.
Mailling list information: http://www.ossec.net/en/mailing_lists.html.