[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[ossec-list] Re: Problem with log_format named
- To: ossec-list@xxxxxxxxxxxxxxxx
- Subject: [ossec-list] Re: Problem with log_format named
- From: "Valerio Daelli" <valerio.daelli@xxxxxxxxx>
- Date: Tue, 18 Sep 2007 16:45:50 +0200
- Authentication-results: mx.google.com; spf=pass (google.com: domain of valerio.daelli@xxxxxxxxx designates 209.85.198.186 as permitted sender) smtp.mail=valerio.daelli@xxxxxxxxx; dkim=pass (test mode) header.i=@xxxxxxxxx
- Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=beta; h=domainkey-signature:received:received:message-id:date:from:to:subject:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; bh=rwEfNCuqQQtjDFCcSZ8rw0Zd7WF6UmC+f6jnXLjuKpc=; b=oUxU9GAWegcYBAgdYtnbnuvXU0fN9lyoptAW5pWYU1yP/JcPYSv6kFsh5vMnproRL9JK+QXLoLw7qajy4IJogOlwnbkQjoO0ZC8qsMQ5BrKkCQzF4J12EwoPgZv1bs28UDdczG6fLet6ipCssjPqb/xocwsDe5H2AAkAFPwVu+I=
Hi Daniel
thanks for your quick response.
A colleague of mine and me have decided that the false positive are 'not
so positive' and probably are worth a notice.
So everything is fine for us.
Thanks a lot
Valerio Daelli
On 9/18/07, Daniel Cid <daniel.cid@xxxxxxxxx> wrote:
>
> Hi Valerio,
>
> Yes, OSSEC can monitor named logs and you need to use the "syslog" log
> format in the config. You need to look at our rules to see what is wrong...
>
> Can you submit the logs that are generating the false positive to us? It would
> be much easier to fix them with that in hand.
>
> Thanks,
>
> --
> Daniel B. Cid
> dcid ( at ) ossec.net
>
>
> On 9/17/07, Valerio Daelli <valerio.daelli@xxxxxxxxx> wrote:
> >
> > Hi
> > we use ossec-hids 1.3 on FreeBSD and we would like to monitor
> > the logs of BIND.
> > If we use a log_format of 'named' the server cannot even start.
> > If we use a log_format of syslog for the log file of named we get tons
> > of false positives.
> > Is it possible on ossec-hids 1.3 to monitor the logs of named?
> > Which log_format should we use?
> > Thanks a lot
> >
> > Valerio Daelli
> >
>
OSSEC home |
Main Index |
Thread Index
OSSEC project: www.ossec.net.
Mailling list information: http://www.ossec.net/en/mailing_lists.html.