OSSEC can't parse greek characters

9 views
Skip to first unread message

Kyriakos Stavridis

unread,
Aug 7, 2020, 5:23:43 AM8/7/20
to ossec-list
Hello everyone,

When I install an agent on a machine, considering I live in Greece, I usually face the problem that windows logs contain some Greek characters and OSSEC server doesn't seem to be able to parse them.

The part of the log that is in Greek (ex. a filename or a usename), after the analysis, is shown as weird characters and rectangles and stuff that of course are not machine readable or human readable.

Does anyone have any suggestion on solving this issue?

Thanks!

dan (ddp)

unread,
Aug 7, 2020, 9:00:12 AM8/7/20
to ossec...@googlegroups.com
OSSEC doesn't really have any support for non-ascii character sets.
Pull requests would be welcome though!

> Thanks!
>
> --
>
> ---
> You received this message because you are subscribed to the Google Groups "ossec-list" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to ossec-list+...@googlegroups.com.
> To view this discussion on the web visit https://groups.google.com/d/msgid/ossec-list/24b17f30-69c5-4c4b-8845-fd272bd92bc9n%40googlegroups.com.

Kyriakos Stavridis

unread,
Aug 13, 2020, 6:21:59 AM8/13/20
to ossec-list
Hello dan, thank you for your response.

My goal is to enable OSSEC to parse utf-8. Isn't there any option that would allow me to do that?

I would really like to contribute to OSSEC and add this myself. Sadly, I do not know how. Do you have any suggestions on how to start or where to look first?

King regards,
K.Stavridis

dan (ddp)

unread,
Aug 18, 2020, 8:23:24 AM8/18/20
to ossec...@googlegroups.com
On Thu, Aug 13, 2020 at 6:22 AM Kyriakos Stavridis
<stavridi...@gmail.com> wrote:
>
> Hello dan, thank you for your response.
>
> My goal is to enable OSSEC to parse utf-8. Isn't there any option that would allow me to do that?
>

Not currently.

> I would really like to contribute to OSSEC and add this myself. Sadly, I do not know how. Do you have any suggestions on how to start or where to look first?
>

I'd probably start by figuring out how various systems support utf8
and where this would have to be added to ossec.

> King regards,
> K.Stavridis
>
> --
>
> ---
> You received this message because you are subscribed to the Google Groups "ossec-list" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to ossec-list+...@googlegroups.com.
> To view this discussion on the web visit https://groups.google.com/d/msgid/ossec-list/8ff56f9e-037a-4a5a-8e76-ab57323ed7d3o%40googlegroups.com.
Reply all
Reply to author
Forward
0 new messages