OSSEC: custom_alert_output with client-syslog

33 views
Skip to first unread message

sushi...@gmail.com

unread,
Aug 31, 2015, 12:13:41 PM8/31/15
to ossec-list
Hello,

I was wondering if it is possible to use the client-syslog tool packaged with OSSEC, when OSSEC is outputting alerts in a custom format. I tried turning it on and using it with the custom formatting but it would not send alerts unless the format of the alert was left alone in its default state. How does OSSEC pull the alerts from the alerts.log ? is it hardcoded with a specific format ?

Thanks,
Jacob

dan (ddp)

unread,
Aug 31, 2015, 9:48:55 PM8/31/15
to ossec...@googlegroups.com
Support for custom log formats was never added to csyslogd. There has
been some initial work to have csyslogd read from the zmq interface,
but it stalled due to time issues.

> Thanks,
> Jacob
>
> --
>
> ---
> You received this message because you are subscribed to the Google Groups
> "ossec-list" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to ossec-list+...@googlegroups.com.
> For more options, visit https://groups.google.com/d/optout.
Reply all
Reply to author
Forward
0 new messages