--
When I open ossec.log I saw that:Remote syslog allowed from: '192.168.10.1'Error: Unable to bind port '514'
I don't know about this problem
can you guide me to config it?
This is starting to border on the absurd. Do you have any linux experience?
On Feb 12, 2015 8:50 PM, "Network Infrastructure" <panhat...@gmail.com> wrote:
>
> when I type in ossec manager: tcpdump -i inside -Xxnnnevvvs 0 port 2514 192.168.11.1 and I also type: tcpdump -i inside -Xxnnnevvvs 0 2514 192.168.11.1
>
You took out the "host" i had provided for you.
> and it show message that:
>
> tcpdump: inside: No such device exists
> (SIOGIFHWADDR: No such device)
>
You used the wrong interface name. Please give me the output of:
`ifconfig -a`
OSSEC is not a turnkey solution, it will require maintenence. So far your technical prowess does not instill confidence.
> On Friday, February 6, 2015 at 9:11:33 AM UTC+7, Network Infrastructure wrote:
>>
>> I have configured OSSEC to monitor my ASA 5520 but I cannot see anything
>>
>> In ASA 5520, I enable syslog server to send syslog to my OSSEC
>>
>>
>> In OSSEC, the /var/ossec/etc/ossec.conf, I configed:
>>
>> <ossec_config>
>>
>> <remote>
>> <connection>syslog</connection>
>> <allowed-ips>IP_OF_CISCO_DEVICE</allowed-ips>
>> </remote>
>> <global>
>> <logall>yes</logall>
>> </global>
>>
>> </ossec_config>
>>
>> Then I restart ossec services but I cannot see anything.
>>
>>
>> Help me please ...
>
On Feb 12, 2015 8:50 PM, "Network Infrastructure" <panhat...@gmail.com> wrote:
>
> When I checked it in /var/ossec/logs/ossec.log I see that:
>
>
> remote syslog allowed from: '192.168.10.1'
>
That was the ip you gave it in the ossec.conf. i believe that should be the ip of your asa device. If it is not, please give me the ip of your asa device so i can give you the configuration you should use.
> So, I think we have problem with decoder file.
>
No, that's absurd. The decoder.xml has nothing tk do with this. Are you trolling?
> On Friday, February 6, 2015 at 9:11:33 AM UTC+7, Network Infrastructure wrote:
>>
>> I have configured OSSEC to monitor my ASA 5520 but I cannot see anything
>>
>> In ASA 5520, I enable syslog server to send syslog to my OSSEC
>>
>>
>> In OSSEC, the /var/ossec/etc/ossec.conf, I configed:
>>
>> <ossec_config>
>>
>> <remote>
>> <connection>syslog</connection>
>> <allowed-ips>IP_OF_CISCO_DEVICE</allowed-ips>
>> </remote>
>> <global>
>> <logall>yes</logall>
>> </global>
>>
>> </ossec_config>
>>
>> Then I restart ossec services but I cannot see anything.
>>
>>
>> Help me please ...
>
I don't see anything but I think I config my ASA working properly.
Seriously... Google is your friend, not your enemy... :-)
But it means tcpdump is in a state where it is capturing traffic, if you don't see anything on screen after that and logs are DEFINATELY being generated on your asa then the asa isn't sending syslog messages to the ip of the OSSEC manager.
I think you need to start considering hiring someone with more experience in this, or looking at providers who you can pay for this kind of service because once (if) you get it all going the amount of logs generated will blow your mind.
--
---
You received this message because you are subscribed to a topic in the Google Groups "ossec-list" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/ossec-list/BEGKABvtmhA/unsubscribe.
To unsubscribe from this group and all its topics, send an email to ossec-list+...@googlegroups.com.