On Wed, Apr 1, 2015 at 7:37 AM, <ecanm...@gmail.com> wrote:
> hi,
>
> First I want that ossec collects all logs.
> I have put the logall options and
> log alertlevel is even at 0
>
>
> <global>
> <logall>yes</logall>
> </global>
>
>
>
> <alerts>
> <log_alert_level>0</log_alert_level>
> <email_alert_level>0</email_alert_level>
> </alerts>
>
>
> stil I don't get all log information, i usually get logs regarding event 3
> (mostly or higher).
>
> what else do I need to do, so OSSEC will log all events?
>
All log messages received by OSSEC should be in
/var/ossec/logs/archives/archives.log. Not all log messages trigger an
alert.
> Second question is about OpenVPN
>
> Can I gather openvpn events to OSSEC?
If it logs to a file you can.
> I tried the rules and decoders but thats just time wasting,
Why is it a wate of time?
> I really don't understand the OSSEC has not standard rules for such a widely
> used program !!
Would you like to know why we don't have rules and decoders for
OpenVPN? It's an easy answer: No one has written and contributed any.
No one has bothered to even contribute log samples. I don't use it.
None of the devs I've chatted with have mentioned it. It's hard to
support something I don't have access to.
Send me log samples, I'll do some work with it.Submit a pull request
with decoders and rules, and I'll make sure they get in. Whine and
I'll do nothing.
you mean something like this and the information will be collected by OSSEC agent (the openvpn is installed on a different server, managed by the client)?
<ossec_config> <localfile> <-- /etc/openvpn/logs/open-vpn.log --> </localfile></ossec_config>
<localfile>
<log_format>syslog</log_format>
<location>/etc/openvpn/log/openvpn.log</location>
</localfile>Wed Apr 1 15:36:35 2015 us=196958 read UDPv4 [ECONNREFUSED]: Connection refused (code=111)I don't get messages like who is logged on or logged off or as in the case above: which connection is refused
spend again much time on this and again at the end no results
sorry but OSSEC is definitely not ready for deployment , OSSEC misses so much and even easy things are so complicated
but I guess that's a common issue with open source , opensource is not for business environment, maybe for hobbies t at home
hope you now understand what I mean and its not whining