Hi,
opened a ticket but portal got closed. posting shuns me.
since the latest ossec update asl gui has no new entries anymore.
ossec-hids restarts periodically every few minutes.
its complaining about a level column in alert table that does not exist.
mysql-db is fine.
thanks
error in latest ossec package?
- mikeshinn
- Atomicorp Staff - Site Admin
- Posts: 4155
- Joined: Thu Feb 07, 2008 7:49 pm
- Location: Chantilly, VA
Re: error in latest ossec package?
That can happen if you're using ASL 3.2.x or older. You'll want to upgrade to 4.x to enjoy the enhancements in OSSEC:
https://www.atomicorp.com/wiki/index.ph ... 3.2_to_4.0
https://www.atomicorp.com/wiki/index.ph ... 3.2_to_4.0
Michael Shinn
Atomicorp - Security For Everyone
Atomicorp - Security For Everyone
Re: error in latest ossec package?
no way around it for now? i would like to avoid just upgrading. i have no time to read through docs now.
does the upgrade leave all the settings of version 3.2.x the way they are? or does it change them?
thanks
does the upgrade leave all the settings of version 3.2.x the way they are? or does it change them?
thanks
Re: error in latest ossec package?

If ASL4 is mandatory why isn't it a dependency or at least mentioned in the release?!
So now I have no real choice than upgrading ASL or downgrading ossec which might cause other errors.

EDIT:
Upgraded.
I was asked about asl console acl IP access. What kind of access should that be and is 127.0.0.1 in this list by default? What is it?
Thanks.
-
- Atomicorp Staff - Site Admin
- Posts: 8355
- Joined: Wed Dec 31, 1969 8:00 pm
- Location: earth
- Contact:
Re: error in latest ossec package?
ASL Console is the port 30000 web interface. You can enter your IP(s) there to restrict access, or if you go with the defaults its open to the world.
Re: error in latest ossec package?
Another one. It was not about the WEB Console Whitelist. I was asked the questions multiple times. The latter was about Web...this one was different and asked at first or second place. I don't have the exact wording in my mind.
EDIT: OK. Mixed it up during the process. Checked the logs and there is only one Console ACL question.
EDIT: OK. Mixed it up during the process. Checked the logs and there is only one Console ACL question.