Ossec and Oracle Logs

21 views
Skip to first unread message

charle...@decisivedge.com

unread,
Feb 5, 2018, 4:10:16 PM2/5/18
to ossec-list
Hello

Has anyone written a rule and decorder for an oracle DB. I know that OSSEC and inject the logs but it seems that OSSEC does not know how to interpret them. Can any help me with this or even point me to a source. Is there anything that I need to do on the DB side ? 

Thanks
Chuck

Bill Price

unread,
Feb 13, 2018, 9:22:33 AM2/13/18
to ossec-list
Hey Chuck,

  I have not actually tried to decode any Oracle logs.  But have you used the ossec-logtest utility?  I have used it to debug several application logging issue.  You can pipe entire logs into it to see how ossec handles it.  But for me, I start off simple.  Start ossec-logtest, then paste a single log entry into it.  It will show you output from each step.  Let me know if this helps

Bill
Reply all
Reply to author
Forward
0 new messages