Von: os-sim-support-bounces
lists.sourceforge.net">os-sim-support-bounces
lists.sourceforge.net Datum: 21. August 2007 21:57:39 GMT+02:00
An: os-sim-support-owner
lists.sourceforge.net">os-sim-support-owner
lists.sourceforge.net Betreff: Auto-discard notification
The attached message has been automatically discarded.
Von: "Alberto Roman" < linazero
gmail.com">linazero
gmail.com> Datum: 21. August 2007 21:57:34 GMT+02:00
An: "Brian Lavender" < brian
brie.com">brian
brie.com>, os-sim-support
lists.sourceforge.net">os-sim-support
lists.sourceforge.net Betreff: Re: [Os-sim-support] Sensor in Web interface
Hi Brian,
Ok, I found the problem. Its the same problem that you had with
arpwatch: plugins are not inserted in the DB.
You just need to insert all the wanted plugins in
/etc/ossim/agent/plugins into the DB, and it will work. It's the same
solution that in my other mail.
The problem is that if the server receives an event regarding some
plugin that doesn't exists in DB, it rejects all the information about
it. This includes the queries from web (like
"server_get_sensor_plugins") or events from agent.
Alberto.
2007/8/21,
Brian Lavender < brian
brie.com">brian
brie.com>: On Sat, Aug 18, 2007 at 11:34:38AM +0200, Dominique Karg wrote:
That's weird, I just checked it here and everything works fine.
If you got to Policy --> Sensors and click on a sensor name, does it
behave the same ?
If I go to Policy -> Sensors, I can click on the sensor name which is
192.168.1.122 and then it comes up with a page like the following.
<h1> Sensors </h1>
<h2 align="center">192.168.1.122 [ cienfuegos ]</h2> <table align="center">
<tr>
<th> Plugin </th>
<th> Status </th>
<th> Action </th>
<th> Enabled </th>
<th> Action </th>
</tr>
</table>
</td>
</tr>
</table>
You can see that no details regarding the plugins is shown. Someone else
emailed me regarding this. I looked at the PHP code, but I haven't
digested it yet, or was I able to find anything glaringly wrong. I
looked at CVS to try and see what changes you made, but I haven't
gotten too far there either.
brian
Greetings,
Dominique
Am 16.08.2007 um 02:23 schrieb Brian Lavender:
It looks like I got snort on one host as a sensor feeding into the
snort
database on another that is running the server/frameworkd. The
problem I
seem to be having now is that Monitors->Sensors shows the sensor on
the
localhost and the sensor running on 192.168.1.122, but it doesn't show
any of the plugins available on either of the sensors. What do I
need to
check here?
brian
--
Brian Lavender
----------------------------------------------------------------------
---
This SF.net email is sponsored by: Splunk Inc.
Still grepping through log files to find problems? Stop.
Now Search log events and configuration files using AJAX and a
browser.
_______________________________________________
Os-sim-support mailing list
Os-sim-sup
port
lists.sourceforge.net">Os-sim-support
lists.sourceforge.net
--
Brian Lavender
-------------------------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc.
Still grepping through log files to find problems? Stop.
Now Search log events and configuration files using AJAX and a browser.
_______________________________________________
Os-sim-support mailing list
Os-sim-sup
port
lists.sourceforge.net">Os-sim-support
lists.sourceforge.net