Re: [logs] OSHids 0.3

From: Daniel Cid (danielcid@private)
Date: Fri May 06 2005 - 08:56:03 PDT


I'm surprised that there is still someone using this
tool. I didn't touch it for more than one year (btw,
I'm the author or it) and haven't heard of anyone
using it (read bellow)...

I completely rewrote it (now in C, using the rules in
XML and with support to "statefull analysis"
(if_matched (timeframe of 360 secs):'changed by null'
and match:'adduser', for example).

I will release the first version of it in a few days
(or weeks -- as soon as I have time to finish some
last things). If someone is interested to test it or
want to start using the "beta" version, let me know :)

But, looking at your problem now... Are you using
OSHIDS for what? Iptables log analysis? Or a simple
log analysis? Can you provide your oshids
configuration files? What system are you using? Is
oshids running? Error messages? :) 
Without some more information it is impossible to help
you...

--
Daniel B. Cid, CISSP
daniel.cid @ ( at ) gmail.com

--- Christabel Apea-Bah
<christabel@private> escreveu:

> Hi,
>  
> I'm using oshids. But my graphs don't come up. For a
> whole day, it
> doesn't generate the logs even though I can see logs
> in
> /var/log/messages.
>  
> Any help will be very much appreciated.
>  
> Thanks.
>  
> Christabel
> > _______________________________________________
> LogAnalysis mailing list
> LogAnalysis@private
> http://lists.shmoo.com/mailman/listinfo/loganalysis
> 


__________________________________________________
Converse com seus amigos em tempo real com o Yahoo! Messenger 
http://br.download.yahoo.com/messenger/ 
_______________________________________________
LogAnalysis mailing list
LogAnalysis@private
http://lists.shmoo.com/mailman/listinfo/loganalysis



This archive was generated by hypermail 2.1.3 : Fri May 06 2005 - 11:33:25 PDT