Questions tagged [ossec]

OSSEC is an Open Source Host-based Intrusion Detection System. It performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response. (from www.ossec.net)

73 questions
1
vote
1 answer

Generating alerts from ossec ( server- agent ) model

I'm very new to OSSEC. I use a server-agent model. I wish to generate alert for the following actions ( in agent side ): 1) Sample Alert for delation of logs I added the rules for these in agent's ossec.conf using tags. Like this : …
batman
  • 321
  • 1
  • 5
  • 10
1
vote
4 answers

OSSEC is not running

I have an two ec2 instances. In one I have installed ossec server and in other I have installed ossec agent. Here are my server config INBOUND (security group/firewall) : port:514 source:0.0.0.0/0 port:1514 source:0.0.0.0/0 But it seems to be…
batman
  • 321
  • 1
  • 5
  • 10
1
vote
2 answers

What dangers (and should I be worried) are there from attempted break-ins? (reported by OSSEC)

I've installed OSSEC on my server and I've been getting reports similar to the following: Jan 11 19:27:03 Daddy sshd[14459]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=58.215.184.93 user=root Jan 11…
Wayne Werner
  • 709
  • 4
  • 14
  • 26
1
vote
0 answers

Where can I find information about inbuilt registry keys for Windows Server 2008 R2?

Is there a resource for looking up the description and/or usage of W2K8 R2 registry keys? I need to understand integrity checksum change messages appearing in OSSEC logs on Amazon EC2…
1
vote
2 answers

Do I need at least 1 Linux server to use OSSEC to monitor my Windows servers?

I don't know why this isn't more plainly obvious on the website: http://www.ossec.net/ But I can't tell if I need to install a 'server' portion on Linux and then an 'agent' on Windows and then monitor through Linux, or if I can use Windows for the…
MetaGuru
  • 856
  • 5
  • 22
  • 35
1
vote
1 answer

HOw to view all Logs in OSSSEC system ubuntu

I have installed OSSEC It is working and sometime sending me alert email as well. But i want to see what can i type so that i can get view all the logs of what OSSEC has found in my system
John
1
vote
0 answers

OSSEC Multiple "Integrity Checksum Changed" Alerts

I know this question has been asked several times, but the answers do not seem to work. After installing OSSEC server on my Ubuntu Server 18.04 LTS machine, I've received hundreds of "Integrity Checksum Changed" alerts regarding files in the…
Leah96xxx
  • 11
  • 3
0
votes
1 answer

Get OSSEC syscheck to alert on change to directory but not its contents

We are running OSSEC 3.2 on some Debian servers. We are using OSSEC's syscheck to alert us when certain files and directories change. I want syscheck to generate an alert when the directory /tmp changes. Now, I don't care about any of /tmp's…
user35042
  • 2,601
  • 10
  • 32
  • 57
0
votes
0 answers

Can I use OSSEC in a home LAN to monitor for intrusion and malwares?

I'm not quite sure I understand what OSSEC does. But after HiddenWasp, I would like to make sure my Windows and Linux machines in my home are safe. (And harden my VPS) Does OSSEC support antimalware scanning/detection ? I couldn't find anything in…
HypeWolf
  • 113
  • 5
0
votes
1 answer

ossec client.keys in the master is missing agent details frequently

I've setup ossec architecture for my client. Most of the agents that were actively reporting to ossec master, moves to disconnected status. On analysis I was able to find out that client.keys the agent details where missing. But not sure why this…
Bharath
  • 1
  • 2
0
votes
1 answer

OSSEC Ignore Alert

I have OSSEC 2.94 setup and running on CentOS7. I have it sending a emails upon qualifying alert conditions. Everything appears to be functioning properly with regards to sending alerts. However, each night as part of a backup process, one server…
MSF004
  • 177
  • 1
  • 1
  • 11
0
votes
1 answer

Linux files permissions denied on log files

I have installed nxlog to send my logs to a graylog server. It works fine, but I have a denied permission on the logs of my HIDS Ossec. My process nxlog (launched by collector-sidecar) run as root : # ps -ef | grep collector root 1869 1 0…
Sorcha
  • 1,315
  • 8
  • 11
0
votes
0 answers

OSSEC - Not seeing alerts on the Server from file changes on the Agent

I have an OSSEC server and Agent installed and configured. I have imported the key to the Agent and they appear to be communicating. However, I am trying test the file integrity monitoring feature and I am not receiving alerts. I followed:…
user8897013
  • 443
  • 1
  • 4
  • 7
0
votes
1 answer

ossec 2.8.3 : getting autentication alerts from Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational

on ossec 2.8.3 I am trying to get alerts only for rdp autentications from windows agents. These events are shown in the clients event log Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational for example with eventID 1149 I have in…
golemwashere
  • 724
  • 1
  • 10
  • 21
0
votes
1 answer

How to stop certain processes from polluting the messages log

We have a certain process related to Azure that is running that is constantly writing out the following to our logs: Aug 18 06:54:28 log-ids-vm rsyslogd-3000: omazuremds error at connect(). errno=No such file or directory How can we stop a certain…
Pat
  • 133
  • 1
  • 9