store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Wed Jun 19, 2013 12:58 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 7 posts ] 
Author Message
 Post subject: ASL Decoder File
Unread postPosted: Wed May 18, 2011 1:33 pm 
Offline
Forum User
Forum User

Joined: Sat Sep 25, 2010 2:46 pm
Posts: 97
We ran into an issue with the test build that is very similar to:

viewtopic.php?f=3&t=4000

The issue appears to have started when we upgraded to the ossec 2.6 rpm.

After looking at the errors generated, we found that we were missing the asl decoder file at:

/var/asl/rules/ossec/etc

Since this is a test box we didn't have another copy of 01-asl-decoder.xml so we used the file from our 2.x ASL install from our other box.

After putting said file in the above folder and in /var/ossec/etc/decoder.d/ we were able to restore OSSEC functionality.

Questions:

Have you had any recent reports of similar issues?

Where can we get the default 01-asl-decoder.xml latest file from so that we aren't running with the 2.0 version (assuming there have been some changes since then)?

Thanks.


Top
 Profile  
 
 Post subject: Re: ASL Decoder File
Unread postPosted: Wed May 18, 2011 6:02 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7458
Location: earth
I dont really know, so far Ive only seen that happen on cpanel.


Top
 Profile  
 
 Post subject: Re: ASL Decoder File
Unread postPosted: Thu May 19, 2011 3:32 pm 
Offline
Forum User
Forum User

Joined: Sat Sep 25, 2010 2:46 pm
Posts: 97
Thanks.

Any way you could post a copy of the default 01-asl-decoder.xml file from the test build?


Top
 Profile  
 
 Post subject: Re: ASL Decoder File
Unread postPosted: Thu May 19, 2011 3:46 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7458
Location: earth
It wouldnt help, its coming from the main decoder.


Top
 Profile  
 
 Post subject: Re: ASL Decoder File
Unread postPosted: Fri May 20, 2011 5:18 pm 
Offline
Forum User
Forum User

Joined: Sat Sep 25, 2010 2:46 pm
Posts: 97
Scott:

Thanks.

Not sure I'm following. Are you saying that the issue originates from the main decoder file (if so, not quite following why adding the 01-asl file allowed OSSEC to function)?


Top
 Profile  
 
 Post subject: Re: ASL Decoder File
Unread postPosted: Fri May 20, 2011 5:27 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7458
Location: earth
Yup thats it exactly


Top
 Profile  
 
 Post subject: Re: ASL Decoder File
Unread postPosted: Sat May 21, 2011 3:32 pm 
Offline
Forum User
Forum User

Joined: Sat Sep 25, 2010 2:46 pm
Posts: 97
Thank you.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 7 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group