I don't find any option to make mysl more talkative (there is no log level option). I thought it could be linked with the number of simultaneous sessions, but I still can connect to with the ossec user myself !
2012/05/14 09:24:57 ossec-dbd: DEBUG: Starting ...
2012/05/14 09:24:57 adding rule: rules_config.xml
2012/05/14 09:24:57 adding rule: pam_rules.xml
2012/05/14 09:24:57 adding rule: sshd_rules.xml
2012/05/14 09:24:57 adding rule: telnetd_rules.xml
2012/05/14 09:24:57 adding rule: syslog_rules.xml
2012/05/14 09:24:57 adding rule: arpwatch_rules.xml
2012/05/14 09:24:57 adding rule: symantec-av_rules.xml
2012/05/14 09:24:57 adding rule: symantec-ws_rules.xml
2012/05/14 09:24:57 adding rule: pix_rules.xml
2012/05/14 09:24:57 adding rule: named_rules.xml
2012/05/14 09:24:57 adding rule: smbd_rules.xml
2012/05/14 09:24:57 adding rule: vsftpd_rules.xml
2012/05/14 09:24:57 adding rule: pure-ftpd_rules.xml
2012/05/14 09:24:57 adding rule: proftpd_rules.xml
2012/05/14 09:24:57 adding rule: ms_ftpd_rules.xml
2012/05/14 09:24:57 adding rule: ftpd_rules.xml
2012/05/14 09:24:57 adding rule: hordeimp_rules.xml
AND ALL THE OTHER RULES...
AND THEN :
2012/05/14 09:24:57 ossec-dbd: DEBUG: Connecting to '127.0.0.1', using 'XXXX', 'XXXXX', 'ossec', 0,'(null)'.
2012/05/14 09:24:57 ossec-dbd: Connected to database 'ossec' at '127.0.0.1'.
2012/05/14 09:24:57 ossec-dbd: DEBUG: entering OS_Server_ReadInsertDB()
2012/05/14 09:24:57 ossec-dbd: Reading rules file: 'rules_config.xml'
2012/05/14 09:24:57 ossec-dbd: DEBUG: read xml for rule '/rules/rules_config.xml'.
2012/05/14 09:24:57 ossec-dbd: DEBUG: XML Variables applied.
2012/05/14 09:24:57 ossec-dbd: DEBUG: entering _Rules_ReadInsertDB()
2012/05/14 09:24:57 ossec-dbd: DEBUG: entering _Groups_ReadInsertDB
2012/05/14 09:24:57 ossec-dbd: DEBUG: entering _Rules_ReadInsertDB()
2012/05/14 09:24:57 ossec-dbd: DEBUG: entering _Groups_ReadInsertDB
2012/05/14 09:24:57 ossec-dbd: DEBUG: entering _Rules_ReadInsertDB()
2012/05/14 09:24:57 ossec-dbd: DEBUG: entering _Groups_ReadInsertDB
2012/05/14 09:24:57 ossec-dbd: DEBUG: entering _Rules_ReadInsertDB()
2012/05/14 09:24:57 ossec-dbd: DEBUG: entering _Groups_ReadInsertDB
2012/05/14 09:24:57 ossec-dbd: DEBUG: entering _Rules_ReadInsertDB()
2012/05/14 09:24:57 ossec-dbd: DEBUG: entering _Groups_ReadInsertDB
2012/05/14 09:24:57 ossec-dbd: DEBUG: entering _Rules_ReadInsertDB()
2012/05/14 09:24:57 ossec-dbd: DEBUG: entering _Groups_ReadInsertDB
2012/05/14 09:24:57 ossec-dbd: DEBUG: entering _Rules_ReadInsertDB()
2012/05/14 09:24:57 ossec-dbd: DEBUG: entering _Groups_ReadInsertDB
2012/05/14 09:24:57 ossec-dbd: Reading rules file: 'pam_rules.xml'
2012/05/14 09:24:57 ossec-dbd: DEBUG: read xml for rule '/rules/pam_rules.xml'.
2012/05/14 09:24:57 ossec-dbd: DEBUG: XML Variables applied.
2012/05/14 09:24:57 ossec-dbd: DEBUG: entering _Rules_ReadInsertDB()
2012/05/14 09:24:57 ossec-dbd: DEBUG: entering _Groups_ReadInsertDB
2012/05/14 09:24:57 ossec-dbd: DEBUG: entering _Rules_ReadInsertDB()
2012/05/14 09:24:57 ossec-dbd: DEBUG: entering _Groups_ReadInsertDB
AND SO ON !
As you can see OSSEC succesfully connects to mysql. I think there must be something with mysql, but because I don't get it's log verbose higher it's not going to be easy.
Any idea ?
On Friday, May 11, 2012 2:09:18 PM UTC+2, dan (ddpbsd) wrote: