Search found 24 matches

by cponton
Tue Jul 06, 2021 9:58 am
Forum: OSSEC
Topic: How to configure ossec.conf in windows agent for directory/file monitoring
Replies: 5
Views: 273

Re: How to configure ossec.conf in windows agent for directory/file monitoring

<directories check_all="yes">E:\.</directories>

The \ should be a / so can you give that a try please?

<directories check all="yes">e:/<directories>
by cponton
Thu Jul 01, 2021 2:51 pm
Forum: OSSEC
Topic: OSSEC Virtual Appliance
Replies: 4
Views: 273

Re: OSSEC Virtual Appliance

Can you verify that kibana is running with ps ax | grep kibana

Also, if you could grep "kibana" /var/log/messages
to see if any errors occur there
by cponton
Thu Jul 01, 2021 12:13 pm
Forum: OSSEC
Topic: OSSEC Virtual Appliance
Replies: 4
Views: 273

Re: OSSEC Virtual Appliance

Do you have an error output that you are seeing after having updated the Kibana service?
by cponton
Mon Jun 14, 2021 8:16 am
Forum: Help with other free stuff
Topic: Evereyone
Replies: 3
Views: 1286

Re: Evereyone

OSSEC supports sending diffs when changes are made to text files on Linux and unix systems. Configuring syscheck to show diffs is simple, add report_changes="yes" to the <directories option. For example: <syscheck> <directories report_changes="yes" check_all="yes">/etc<...
by cponton
Thu Jun 10, 2021 9:11 am
Forum: Help with other free stuff
Topic: Evereyone
Replies: 3
Views: 1286

Re: Evereyone

Yes! You will need to vim into /var/ossec/etc/ossec.conf and modify the file to include what directories you would like to watch: <!-- Directories to check (perform all possible verifications) --> <directories check_all="yes">/etc,/usr/bin,/usr/sbin</directories> <directories check_all=&qu...
by cponton
Tue Jun 08, 2021 8:40 am
Forum: OSSEC
Topic: How do I connect OSSEC Server and Client together in Virtualbox?
Replies: 4
Views: 1060

Re: How do I connect OSSEC Server and Client together in Virtualbox?

Verify that you can ping the server box from the agent. A lot of times, when the HUB cannot detect the agent, it is because of either a firewall or a closed port.

Here are the documents for connecting agents to the HUB. https://www.ossec.net/docs/docs/manual/agent/index.html
by cponton
Fri May 28, 2021 5:44 pm
Forum: OSSEC
Topic: ERROR: Download failed with ERROR (6)
Replies: 6
Views: 1906

Re: ERROR: Download failed with ERROR (6)

If you would like to try changing the password for the account, you can do so here:
www.atomicorp.com/amember/login

Once changed, update the oum.conf directly and then try and run oum update
by cponton
Mon May 24, 2021 8:28 am
Forum: OSSEC
Topic: ERROR: Download failed with ERROR (6)
Replies: 6
Views: 1906

Re: ERROR: Download failed with ERROR (6)

Please go into the oum file at /var/ossec/etc/oum.conf and verify that the credentials have been input to the file and that they are correct. make any changes needed and then save the file.

The run oum update
by cponton
Thu May 20, 2021 9:45 am
Forum: Atomic Protector (formerly ASL)
Topic: ASL Kernel Status
Replies: 9
Views: 2858

Re: ASL Kernel Status

We do not have any documentation on the module at this time, no. When one is available, we will it post here.
by cponton
Thu May 20, 2021 9:10 am
Forum: OSSEC
Topic: TLS Support for OSSEC agent/master comms?
Replies: 1
Views: 1106

Re: TLS Support for OSSEC agent/master comms?

Hello!

Both agent registration and communication are AES256 encrypted and handled via TLS by default
https://docs.atomicorp.com/AEO/index.html
by cponton
Fri Apr 16, 2021 9:12 am
Forum: OSSEC
Topic: oum update ERROR: Download failed with ERROR (6)
Replies: 5
Views: 2413

Re: oum update ERROR: Download failed with ERROR (6)

Please verify your credentials are entered correctly in /var/ossec/oum.conf

If you believe you may need a password reset, please email us at support@atomicorp.com so we can send that to your privately. Thanks!
by cponton
Mon Apr 12, 2021 9:05 am
Forum: OSSEC
Topic: ossec+
Replies: 3
Views: 2179

Re: ossec+

sp0k wrote: Sat Apr 10, 2021 6:13 pm Hi,
I've got the same problem. Tried with 2 different accounts but the problem remain.
I will be sending you an email from our support channel to assist with your issues.
by cponton
Thu Mar 18, 2021 8:22 am
Forum: OSSEC
Topic: oum install kofe: "no match"
Replies: 6
Views: 2714

Re: oum install kofe: "no match"

Only CentOS 7/8 and RHEL 7/8 are supported at this time for the OSSEC+ HUB. Ubuntu boxes can be added as agents, though.
by cponton
Tue Mar 02, 2021 10:38 am
Forum: OSSEC
Topic: ossec+
Replies: 3
Views: 2179

Re: ossec+

Hello!

Please verify the email you signed up under. If you would prefer, you can send that email to support@atomicorp.com and we can help you there so to keep your info private.
Thanks!