Ossec disconnected ! Alarm interrupt transmission interval too long!

26 views
Skip to first unread message

hxh...@gmail.com

unread,
Jul 10, 2014, 10:06:28 PM7/10/14
to ossec...@googlegroups.com
To test, service ossec stop,
To receive e-mail alerts after 30 minutes,
The alarm for too long,
Hackers enough to do a lot of things,
How to modify the alarm time shorter? Thank you
 
Rule:504 fired   "Ossec agent disconnected"

dan (ddp)

unread,
Jul 11, 2014, 7:55:03 AM7/11/14
to ossec...@googlegroups.com
On Thu, Jul 10, 2014 at 10:06 PM, <hxh...@gmail.com> wrote:
> To test, service ossec stop,
> To receive e-mail alerts after 30 minutes,
> The alarm for too long,
> Hackers enough to do a lot of things,
> How to modify the alarm time shorter? Thank you
>

There are some timeouts in the source. I'm sure if you search the
archives you can find what to change specifically.

> Rule:504 fired "Ossec agent disconnected"
>
> --
>
> ---
> You received this message because you are subscribed to the Google Groups
> "ossec-list" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to ossec-list+...@googlegroups.com.
> For more options, visit https://groups.google.com/d/optout.

hxh...@gmail.com

unread,
Jul 14, 2014, 1:48:50 AM7/14/14
to ossec...@googlegroups.com
I am looking for a few laps, or did not find this approach

dan (ddp)

unread,
Jul 14, 2014, 7:48:35 AM7/14/14
to ossec...@googlegroups.com
On Mon, Jul 14, 2014 at 1:48 AM, <hxh...@gmail.com> wrote:
> I am looking for a few laps, or did not find this approach
>

I only spent about 3 minutes looking, but try src/headers/defs.h: NOTIFY_TIME
Reply all
Reply to author
Forward
0 new messages