Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Windows agent & custom alerts #2074

Open
securemoi opened this issue Jan 20, 2023 · 4 comments
Open

Windows agent & custom alerts #2074

securemoi opened this issue Jan 20, 2023 · 4 comments

Comments

@securemoi
Copy link

Hi All: I am struggling to get windows alerts to work for custom events. On a couple of windows 10 clients I have added a couple of events but can't get them to come back as alerts. I am using a debian server, and I believe "canned" windows events work (e.g., windows user log ins and logouts) as I am getting alerts from the windows clients to my email and in the ossec archive.log. I've tried adding rules on both the client and server side but no joy. Happy to share configs, but was thinking maybe the place to start with examples that "work" for others...

Q is there a link someone could share as to how to come at this? Hopefully a step by step, with examples.

Thx

@wolle604
Copy link

Hi,

that sounds really like a configuration problem. Did you tried troubleshooting with ossec-logtest? https://ossec-documentation.readthedocs.io/en/latest/legacy/docs/programs/ossec-logtest.html?highlight=logtest

Best wishes

@securemoi
Copy link
Author

securemoi commented Jan 31, 2023 via email

@securemoi
Copy link
Author

securemoi commented Feb 2, 2023 via email

@securemoi
Copy link
Author

securemoi commented Feb 2, 2023 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants