<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
      <title>AlienVault OSSIM Forums</title>
      <link>http://forums.alienvault.com/discussions/feed.rss</link>
      <pubDate>Sun, 26 May 2013 04:05:23 +0000</pubDate>
         <description>AlienVault OSSIM Forums</description>
   <language>en-CA</language>
   <atom:link href="http://forums.alienvault.com/discussions/feed.rss" rel="self" type="application/rss+xml" />
   <item>
      <title>Snort with registered rules</title>
      <link>http://forums.alienvault.com/discussion/1292/snort-with-registered-rules</link>
      <pubDate>Fri, 24 May 2013 06:43:51 +0000</pubDate>
      <category>Sensor</category>
      <dc:creator>TheHoff</dc:creator>
      <guid isPermaLink="false">1292@/discussions</guid>
      <description><![CDATA[Hi folks<div>I've been doing some testing over the last few days and think I'm starting to get a working setup. It's a two part setup with one computer as dedicated sensor running snort and one VMware server running a full setup. Alienvault version is the latest 4.2.2 on both.</div><div>I get a lot of the Emerging rules from snort generating SIEM events but none of my subscriber rules. I've done the setups from this forum post&nbsp;<a rel="nofollow" href="https://www.alienvault.com/forum/index.php?t=rview&amp;th=677&amp;goto=4090">https://www.alienvault.com/forum/index.php?t=rview&amp;th=677&amp;goto=4090</a>&nbsp;and rules are pulled OK byt oinkmaster on both servers and parsed into the database. There are a few snort.conf on /etc/snort and subfolders but none seems to affect the events generated so it feels like I'm missing a "master" .conf somewhere.</div><div><br /></div><div>Can anyone help me out?</div><div><br /></div><div>Regads</div><div>Fredrik</div>]]></description>
   </item>
   <item>
      <title>Vmware tools install (open source or vmware proper)</title>
      <link>http://forums.alienvault.com/discussion/1177/vmware-tools-install-open-source-or-vmware-proper</link>
      <pubDate>Fri, 26 Apr 2013 19:13:41 +0000</pubDate>
      <category>Installation</category>
      <dc:creator>ilom</dc:creator>
      <guid isPermaLink="false">1177@/discussions</guid>
      <description><![CDATA[I must be blind as I find it hard to believe a product primarily deployed in vm's doesnt have a simple way to install vmware tools.&nbsp; I'm using 4.2, hopefully someone can enlighten me on my ignorance.<br /><br />So far I've attempted to jailbreak then apt-get install build-essential...failed (pkg not found; likely sources)<br /><br />Also tried alientvault_dpkg and wget individual files and was met with numerous errors.<br /><br />As it appears I'm clearly going down the wrong road I figured I'd ask before breaking this install just to get vmware tools running.<br /><br />Thanks in advance, ilom<br />]]></description>
   </item>
   <item>
      <title>Single Ascii Character in /var/ossec/logs/alerts/alerts.log file?</title>
      <link>http://forums.alienvault.com/discussion/1296/single-ascii-character-in-varosseclogsalertsalerts-log-file</link>
      <pubDate>Fri, 24 May 2013 19:09:54 +0000</pubDate>
      <category>Deployment Architecture</category>
      <dc:creator>MarsAttack</dc:creator>
      <guid isPermaLink="false">1296@/discussions</guid>
      <description><![CDATA[<p>All,</p><p>I'm curious if anyone has been finding this single ascii character in their logs: ò</p><p>I quick way to check would be to:<br />cat /var/ossec/logs/alerts/alerts.log | grep -v "AV"<br /></p><p>I haven't tracked down the source yet, thought I'd ask.</p>]]></description>
   </item>
   <item>
      <title>OSSIM 4.2: OSSEC Agent Client Update Required Too?</title>
      <link>http://forums.alienvault.com/discussion/1297/ossim-4-2-ossec-agent-client-update-required-too</link>
      <pubDate>Fri, 24 May 2013 19:52:20 +0000</pubDate>
      <category>Deployment Architecture</category>
      <dc:creator>MarsAttack</dc:creator>
      <guid isPermaLink="false">1297@/discussions</guid>
      <description><![CDATA[<p>All,</p><p>Anyone having issues with their 2.5 agents working with OSSEC Server 2.7? I'm curious if there is any benefit to upgrading the ossec agents.</p>]]></description>
   </item>
   <item>
      <title>How to configure OSSEC agent for windows</title>
      <link>http://forums.alienvault.com/discussion/1286/how-to-configure-ossec-agent-for-windows</link>
      <pubDate>Thu, 23 May 2013 06:21:17 +0000</pubDate>
      <category>[N|W|H]IDS</category>
      <dc:creator>Ruslan</dc:creator>
      <guid isPermaLink="false">1286@/discussions</guid>
      <description><![CDATA[Hi all. 
There is one problem with ossec agent. Agent is connected to the server. In the web consol it  has active status, but there is no events from this host(( thanks in advance

2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\Windows/win.ini'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\Windows/system.ini'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\autoexec.bat'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\config.sys'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\boot.ini'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/CONFIG.NT'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/AUTOEXEC.NT'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/at.exe'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/attrib.exe'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/cacls.exe'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/debug.exe'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/drwatson.exe'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/drwtsn32.exe'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/edlin.exe'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/eventcreate.exe'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/eventtriggers.exe'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/ftp.exe'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/net.exe'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/net1.exe'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/netsh.exe'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/rcp.exe'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/reg.exe'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory:
 'C:\Windows/regedit.exe'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/regedt32.exe'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/regsvr32.exe'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/rexec.exe'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/rsh.exe'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/runas.exe'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/sc.exe'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/subst.exe'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/telnet.exe'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/tftp.exe'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/tlntsvr.exe'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/drivers/etc'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\Documents and Settings/All Users/Start Menu/Programs/Startup'.
2013/05/23 07:59:27 ossec-agent: INFO: Monitoring directory: 'C:\Users/Public/All Users/Microsoft/Windows/Start Menu/Startup'.
2013/05/23 07:59:27 ossec-agent: INFO: Started (pid: 412).
2013/05/23 07:59:28 ossec-agent(4102): INFO: Connected to the server (172.16.2.159:1514).
2013/05/23 07:59:28 ossec-agent Sending keep alive message....

There is agent log]]></description>
   </item>
   <item>
      <title>Cisco ASA log to OSSIM</title>
      <link>http://forums.alienvault.com/discussion/1175/cisco-asa-log-to-ossim</link>
      <pubDate>Fri, 26 Apr 2013 17:39:18 +0000</pubDate>
      <category>Installation</category>
      <dc:creator>oelnak</dc:creator>
      <guid isPermaLink="false">1175@/discussions</guid>
      <description><![CDATA[<span><span>Hi Community,&nbsp;</span></span><div><span><span><br /></span></span></div><div><span><span>A newbie here, asking for some help on 'how to collect cisco ASA logs in OSSIM'.</span></span><div>I searched it in the discussions, but could not find the solution.</div><div><br /></div><div>Here is what i did so far:</div><div>-----------------------------------------</div><div><div><span><span>1) Download the ISO V4.2, deploy it into a Virtual Machine "ossim - 10.0.0.10";</span></span></div><div><span><span><br /></span></span></div><div><span><span>2) Ssh into 10.0.0.10, in the AlienValut setup, enable 'cisco-asa' in the 'Configure Sensor' section, then apply changes;</span></span></div><div><span><span><br /></span></span></div><div><span><span>3) Ssh into 10.0.0.10, choose 'Jailbrea this Appliance' in order to update the files;</span></span></div><div><span><span><br /></span></span></div><div><span><span>4) in the folder /etc/rsyslog.d, create a new file 'cisco-asa.conf' with the following 2 lines: &nbsp;</span></span></div><div><span><span>if $fromhost-ip == 10.0.0.1 then -/var/log/cisco-asa.log</span></span></div><div><span><span>if $fromhost-ip == 10.0.0.1 then ~</span></span></div><div><span><span><br /></span></span></div><div><span><span>5) in the folder /etc/ossim/agent/plugins, edit 'cisco-asa.cfg' to the following:</span></span></div><div><span><span>...</span></span></div><div><span><span>location=/var/log/cisco-asa.log</span></span></div><div><span><span>create_file=true</span></span></div><div><span><span>...</span></span></div><div><span><span><br /></span></span></div><div><span><span>6) log rotation: edit the file '/etc/logrotate.d/rsyslog', and add '/var/log/cisco-asa.log' right under '/var/log/syslog';</span></span></div><div><span><span><br /></span></span></div><div><span><span>7) go to my cisco ASA firewall 10.0.0.1, set the syslog server 10.0.0.10;</span></span></div><div><span><span><br /></span></span></div><div><span><span>8) in the 'ossim - 10.0.0.10', i can see the logs from Cisco ASA 10.0.0.1 in the file /var/log/syslog, but not in the /var/log/cisco-asa.log;</span></span></div><div>-------------------------------------------</div></div><div><br /></div><div>Questions:&nbsp;</div><div>-Did i do something wrong?</div><div>-Did i miss any steps needed?</div><div>-Why the cisco ASA's logs kept going into /var/log/syslog instead of /var/log/cisco-asa.log?</div><div><br /></div><div><br /></div><div>Thanks much in advance for all the help!</div><div><br /></div><div><br /></div></div>]]></description>
   </item>
   <item>
      <title>AlienVault - USM OSSEC Error</title>
      <link>http://forums.alienvault.com/discussion/1262/alienvault-usm-ossec-error</link>
      <pubDate>Thu, 16 May 2013 17:58:45 +0000</pubDate>
      <category>[N|W|H]IDS</category>
      <dc:creator>Jared</dc:creator>
      <guid isPermaLink="false">1262@/discussions</guid>
      <description><![CDATA[When attempting the following command:<br /><br />alienvault4sim:/# /var/ossec/bin/ossec-authd -p 1515<br /><br />I receive the following error:<br /><br />ERROR: Not compiled. Missing OpenSSL support.<br /><br />Upgrading the libssl-dev, reinstalling the ossec-hids package causes the AlienVault USM server GIU some significant issues. I recovered the server from backup and would now like to use ossec-authd to register agents.<br /><br />What is the process to recompile OSSEC on the USM now that OpenSSL packages are present? Everything that I have tried has failed and I am still waiting on an answer from the support ticket system.<br /><br />Thank you, <br /><br />Jared <br /><br />]]></description>
   </item>
   <item>
      <title>Using OSSIM vs Alienvault Pro in Production</title>
      <link>http://forums.alienvault.com/discussion/1283/using-ossim-vs-alienvault-pro-in-production</link>
      <pubDate>Wed, 22 May 2013 17:01:13 +0000</pubDate>
      <category>Deployment Architecture</category>
      <dc:creator>cshrimpt</dc:creator>
      <guid isPermaLink="false">1283@/discussions</guid>
      <description><![CDATA[Alienvault says the OSSIM product is for testing an not suitable for 
production. Is anyone using OSSIM in production? I have about a dozen 
sites mostly with 2 MB Internet connections that I'd like to monitor. 
Even using the base Pro version would be prohibitively expensive for so 
many small sites.<br /><br />What's the max traffic/events the free version will support? <br /><br />Thanks]]></description>
   </item>
   <item>
      <title>Suricata or Snort</title>
      <link>http://forums.alienvault.com/discussion/1260/suricata-or-snort</link>
      <pubDate>Thu, 16 May 2013 12:37:39 +0000</pubDate>
      <category>Deployment Architecture</category>
      <dc:creator>ngiannoulis</dc:creator>
      <guid isPermaLink="false">1260@/discussions</guid>
      <description><![CDATA[On my new install of OSSIM 4.2 it looks as Suricata is enabled by default and Snort is disabled ( confusing by the way that Suricata events come under the snort category though ) so my question is shall i leave the current config as it is or would Snort better?<br />]]></description>
   </item>
   <item>
      <title>External OCS</title>
      <link>http://forums.alienvault.com/discussion/1295/external-ocs</link>
      <pubDate>Fri, 24 May 2013 15:13:33 +0000</pubDate>
      <category>Asset Discovery</category>
      <dc:creator>clems</dc:creator>
      <guid isPermaLink="false">1295@/discussions</guid>
      <description><![CDATA[Hello,<br /><br />We have an ocs server with all our assets, I would like to use his DB for OSSIM.<br /><br />I try this:<br />1. edit /etc/apache2/conf.d/ocsinventory.conf&nbsp; to put the DB information<br />2. edit /usr/share/ossim/www/ocsreports/dbconfig.inc.php to put the DB information<br /><br />But none asset was add to OSSIM and when i do&nbsp; ossim-reconfig both files are back with default informations.<br /><br />Question: How to use an external ocsinventory to populate all assets in OSSIM.<br /><br />Regards, <br />]]></description>
   </item>
   <item>
      <title>Any luck with automatic ossec deployment?</title>
      <link>http://forums.alienvault.com/discussion/1289/any-luck-with-automatic-ossec-deployment</link>
      <pubDate>Thu, 23 May 2013 17:28:49 +0000</pubDate>
      <category>Configuring data sources</category>
      <dc:creator>kilgore</dc:creator>
      <guid isPermaLink="false">1289@/discussions</guid>
      <description><![CDATA[Has anyone had any success with the automated ossec deployment feature released in 4.2?<br />I have tried with a brand new windows 7 machine, and get the following errors:<br /><br />Error! Task could not be completed.<br />Error stopping the ossec-agent<br /><br />and <br /><br />Ossec installation failed.&nbsp; Please make sure that:<br />xp or above, credentials, etc, etc....<br /><br /><br />I had AV support look into it for me and they suspect it's a bug, but I'm wondering if anyone else has the same issue.&nbsp; <br /><br />Thanks!<br />]]></description>
   </item>
   <item>
      <title>Problems with Email - Some go, some don't - OSSIM 4.2</title>
      <link>http://forums.alienvault.com/discussion/1203/problems-with-email-some-go-some-dont-ossim-4-2</link>
      <pubDate>Thu, 02 May 2013 15:18:04 +0000</pubDate>
      <category>Reporting</category>
      <dc:creator>aegis</dc:creator>
      <guid isPermaLink="false">1203@/discussions</guid>
      <description><![CDATA[<p>Hello to anyone that can help me.&nbsp; I'm certainly not a noob, but by no means a Linux Novice.&nbsp; I have the AV 4.2 Server setup, and I'm having email issues.&nbsp; Here is what is working, and what is not:</p><p>Email Alerts from Nagios - Yes - from <a rel="nofollow" href="mailto:root@localhost">root@localhost</a> though.... :|</p><p>Email Alerts for CRON - Yes - from <a rel="nofollow" href="mailto:root@localhost">root@localhost</a> though...</p><p>Email Reports from the Reports Section - No</p><p>Email&nbsp;Alerts from OSSEC - No</p><p>I use MS Exchange 2010 SP2 - I have a receive connector setup for the AV Server to relay through, but I'm not sure which authentication mechanisms to enable, and I have never heard of SASL authentication before.</p><p>I have to edit the Postfix Main.cf and turn off authentication to get the Nagios and Cron to work, and after changing /etc/aliases and SASL_password file, things still don't work.&nbsp; </p><p>My Questions:</p><p>Are there other places to configure the email connection for OSSEC and Reports Section?</p><p>How do I get this SASL authentication to work with Exchange?</p><p>How can I make this device send as <a rel="nofollow" href="mailto:HOSTNAME@MYDOMAIN.COM">HOSTNAME@MYDOMAIN.COM</a> rather than <a rel="nofollow" href="mailto:root@localhost">root@localhost</a>?</p><p>Thanks for anyone that will help me with this, your assistance is greatly appreciated!</p><p>Here is Main.cf:</p><p>smtpd_banner = $myhostname ESMTP $mail_name (Alienvault/OSSIM)<br />biff = no<br />append_dot_mydomain = no<br />readme_directory = no<br />mailbox_size_limit = 0<br />recipient_delimiter = +<br />inet_interfaces = loopback-only</p><p>smtpd_tls_cert_file=/etc/ssl/certs/ssl-cert-snakeoil.pem<br />smtpd_tls_key_file=/etc/ssl/private/ssl-cert-snakeoil.key<br />smtpd_use_tls=no<br />smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache<br />smtp_tls_session_cache_database = btree:${data_directory}/smtp_scache<br />smtp_tls_note_starttls_offer = yes<br />tls_random_source = dev:/dev/urandom</p><p>myhostname = tron.lab.local</p><p>myorigin = $myhostname<br />alias_maps = hash:/etc/aliases<br />alias_database = hash:/etc/aliases<br /></p><p>Here is OSSIM_Setup.conf</p><p>admin_dns=10.10.10.200<br />admin_gateway=10.10.10.250<br />admin_ip=10.10.10.219<br />admin_netmask=255.255.255.0<br />domain=joelsitlab.com<br /><a rel="nofollow" href="mailto:email_notify=joel@joelsitlab.com">email_notify=joel@joelsitlab.com</a><br />hostname=tron<br />interface=eth0<br />mailserver_relay=10.10.10.200<br />mailserver_relay_passwd=**omitted-for-security**<br />mailserver_relay_port=25<br />mailserver_relay_user=tron<br />ntp_server=no<br />profile=Server,Sensor,Framework,Database</p><p>[database]<br />db_ip=127.0.0.1<br />pass=***********<br />user=root<br /></p><p>&nbsp;</p>]]></description>
   </item>
   <item>
      <title>OSSEC detect account management like password change etc.</title>
      <link>http://forums.alienvault.com/discussion/1293/ossec-detect-account-management-like-password-change-etc</link>
      <pubDate>Fri, 24 May 2013 08:31:49 +0000</pubDate>
      <category>[N|W|H]IDS</category>
      <dc:creator>shad</dc:creator>
      <guid isPermaLink="false">1293@/discussions</guid>
      <description><![CDATA[I've setup OSSIM 4.2 and latest OSSEC&nbsp; 2.7 on a windows 2003 domain controller, i already see the event in my siem console comming from this agent. <br /><br />I only see events like user sucessfully logged in/out. I would like to see other event like passwords changed, user account  added, user account deleted, user added to group etc. Where can i set all these parameters ?<br /><br />Current config contatins security log:<br /><br />&lt;ossec_config&gt;<br /><br />&nbsp; ...<br />&nbsp; &lt;localfile&gt;<br />&nbsp;&nbsp;&nbsp; &lt;location&gt;Security&lt;/location&gt;<br />&nbsp;&nbsp;&nbsp; &lt;log_format&gt;eventlog&lt;/log_format&gt;<br />&nbsp; &lt;/localfile&gt;<br />...<br /><br />I presumed that this would foerward all the events, but it doesn't.<br /><br />Any help is great. Thank you in advance.<br /><br /><br />]]></description>
   </item>
   <item>
      <title>test - delete me</title>
      <link>http://forums.alienvault.com/discussion/1294/test-delete-me</link>
      <pubDate>Fri, 24 May 2013 11:35:43 +0000</pubDate>
      <category>Compliance</category>
      <dc:creator>iamfromit</dc:creator>
      <guid isPermaLink="false">1294@/discussions</guid>
      <description><![CDATA[<div><span><span><b>please delete me</b></span></span></div>]]></description>
   </item>
   <item>
      <title>How to setup IP Reputation policy?</title>
      <link>http://forums.alienvault.com/discussion/1241/how-to-setup-ip-reputation-policy</link>
      <pubDate>Tue, 14 May 2013 03:23:38 +0000</pubDate>
      <category>SIEM / Console</category>
      <dc:creator>morpheusc</dc:creator>
      <guid isPermaLink="false">1241@/discussions</guid>
      <description><![CDATA[<span><span>How to setup IP Reputation policy? Where I can find the Severity of the event?</span></span>]]></description>
   </item>
   <item>
      <title>Correlation using timeout (absence) of a log event</title>
      <link>http://forums.alienvault.com/discussion/1272/correlation-using-timeout-absence-of-a-log-event</link>
      <pubDate>Mon, 20 May 2013 11:52:05 +0000</pubDate>
      <category>Correlation Help</category>
      <dc:creator>fredrik</dc:creator>
      <guid isPermaLink="false">1272@/discussions</guid>
      <description><![CDATA[Hello!<div><br /></div><div>I am wondering if it is possible to setup AV-USM / OSSIM to correlate on the absence of an expected event using a timeout.</div><div><br /></div><div>Say for instance I'm monitoring a log file and log event "First" shows up. Then I'm expecting log event "Second" to show up within a given time, and if it doesn't, I'd like to generate an alarm/ticket.</div>]]></description>
   </item>
   <item>
      <title>I can't see Snort as a Data Source in the Security Events</title>
      <link>http://forums.alienvault.com/discussion/1290/i-cant-see-snort-as-a-data-source-in-the-security-events</link>
      <pubDate>Thu, 23 May 2013 19:58:14 +0000</pubDate>
      <category>Configuring data sources</category>
      <dc:creator>Seif</dc:creator>
      <guid isPermaLink="false">1290@/discussions</guid>
      <description><![CDATA[Hi again,<div>i had a little problem with my UI.</div><div>I activated Snort from the terminal, and i can see that it's activated in my UI (Deployement -&gt; Sensor Configuration -&gt; Detection) but when i go to the Security Events, i can't see it in the Data Sources .. and i have 0 events from snort ..</div>]]></description>
   </item>
   <item>
      <title>credentialed scan in AD</title>
      <link>http://forums.alienvault.com/discussion/1245/credentialed-scan-in-ad</link>
      <pubDate>Tue, 14 May 2013 14:05:38 +0000</pubDate>
      <category>Vulnerability Assessment</category>
      <dc:creator>iworkhere</dc:creator>
      <guid isPermaLink="false">1245@/discussions</guid>
      <description><![CDATA[<p>Hello everyone</p><p>I have setup OSSIM in an AD environment and am trying to do a credentialed vulnerability scan and it doesnt seem to work.&nbsp; After sniffing the traffic it seems that its using a work group (seems like workgroupalienvault or something like that.&nbsp; i have tried to do a few different things to authenticate my credentials "domain\user" "user" etc and nothing works.</p><p>&nbsp;</p><p>Does anyone have any fixes for this?</p>]]></description>
   </item>
   <item>
      <title>exclude  Host operating system change</title>
      <link>http://forums.alienvault.com/discussion/1291/exclude-host-operating-system-change</link>
      <pubDate>Thu, 23 May 2013 20:19:31 +0000</pubDate>
      <category>SIEM / Console</category>
      <dc:creator>iworkhere</dc:creator>
      <guid isPermaLink="false">1291@/discussions</guid>
      <description><![CDATA[<p>Hello everyone, i have multiple events called</p><p>&nbsp;Host operating system change</p><p>and would like to filter them out of the SIEM view.&nbsp; I tried to do this through the policy but cant find how.&nbsp; Can anyone show me how to simply filter this please?</p><p>&nbsp;</p><p>Thank you,</p>]]></description>
   </item>
   <item>
      <title>Hardware requirements</title>
      <link>http://forums.alienvault.com/discussion/1288/hardware-requirements</link>
      <pubDate>Thu, 23 May 2013 16:58:30 +0000</pubDate>
      <category>Deployment Architecture</category>
      <dc:creator>Max</dc:creator>
      <guid isPermaLink="false">1288@/discussions</guid>
      <description><![CDATA[Hi Community,<div><div><br /></div><div>A newbie here, asking for some help on what hardware config is necessary for the following load,<br /></div><div>&nbsp;</div><div><div>Siem 'office core' &nbsp;- 1300 hosts</div><div>Remote Sensor 'office&nbsp;<span>2' - 850 hosts&nbsp;</span></div><div>Remote Sensor '<span>office&nbsp;</span><span>3' - 450 hosts</span></div><div>Remote Sensor '<span>offcie&nbsp;</span><span>4' - 250 hosts</span></div></div><div><br /></div><div><span>We want to do it with the correct &nbsp;hard so we dont get any problems later,&nbsp;</span><br /></div><div><span>If you can give me an idea&nbsp;</span><span>I</span><span>&nbsp;would be grateful.</span></div><div><span><br /></span></div><div><span>Is Open OSSIM supported by vmware?</span></div><div><span><br /></span></div><div><span>Thanks in advance</span></div><div><span>Regards</span></div><div><br /></div><div><br /></div><div><span><br /></span></div><div><span><br /></span></div><div><span><br /></span></div><div><br /></div><div><br /></div></div>]]></description>
   </item>
   <item>
      <title>eth0 and eth1 problem</title>
      <link>http://forums.alienvault.com/discussion/1284/eth0-and-eth1-problem</link>
      <pubDate>Wed, 22 May 2013 23:00:36 +0000</pubDate>
      <category>Installation</category>
      <dc:creator>Seif</dc:creator>
      <guid isPermaLink="false">1284@/discussions</guid>
      <description><![CDATA[Well, hi all<br />I was using ossim 4.1 and it was Ok .. the port mirroring, snort ..etc<br /><br />I decided to install ossim 4.2 and then i had a big problem.<br />In the installation, i can only choose only one interface for the administration and the promisc mode ..<br />I explain, in the first step i choosed eth0 for the administration interface .. and when it asks me to choose the interface for snort and promisc mode, i tried eth1 .. but i got an error message, a message like : "Snort try to use an inexisting or inactive interface, he's using a default value or the adress is invalid" .. <br />So i can only pass this step if i choose eth0 ..<br /><br />I'm using Vmware Workstation, and i have 2 Network Adapter (Bridged mode) ..<br />I tried a manual configuration but i got this error :<br /><br /><br /><img src="http://img15.hostingpics.net/pics/290875ossim1.png" alt="image" /><br />]]></description>
   </item>
   <item>
      <title>New LDAP Error After Applying Updates Today</title>
      <link>http://forums.alienvault.com/discussion/737/new-ldap-error-after-applying-updates-today</link>
      <pubDate>Fri, 21 Dec 2012 15:03:33 +0000</pubDate>
      <category>Updates &amp; Upgrades</category>
      <dc:creator>mrhaag</dc:creator>
      <guid isPermaLink="false">737@/discussions</guid>
      <description><![CDATA[Warning: ldap_search(): Search: Operations error in /usr/share/ossim/include/classes/Session.inc on line 1169 Warning: ldap_get_entries() expects parameter 2 to be resource, boolean given in /usr/share/ossim/include/classes/Session.inc on line 1170 <br /><br />The above warning happens after I attempt to log in with an LDAP account. I can no longer use LDAP accounts to log in to the web interface. Before updating this morning, I was able to authenticate via LDAP.<br /><br />current version : <br /><br />ii&nbsp; ossim-framework&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 1:4.1.2-127 <br />]]></description>
   </item>
   <item>
      <title>Can OSSIM be installed on an already built Windows 7 system without wiping the disk?</title>
      <link>http://forums.alienvault.com/discussion/1281/can-ossim-be-installed-on-an-already-built-windows-7-system-without-wiping-the-disk</link>
      <pubDate>Wed, 22 May 2013 10:34:35 +0000</pubDate>
      <category>Installation</category>
      <dc:creator>carwin</dc:creator>
      <guid isPermaLink="false">1281@/discussions</guid>
      <description><![CDATA[Can OSSIM be installed on an already built Windows 7 system without wiping the disk?]]></description>
   </item>
   <item>
      <title>Feature Request</title>
      <link>http://forums.alienvault.com/discussion/1287/feature-request</link>
      <pubDate>Thu, 23 May 2013 14:05:06 +0000</pubDate>
      <category>Product</category>
      <dc:creator>gio_martins</dc:creator>
      <guid isPermaLink="false">1287@/discussions</guid>
      <description><![CDATA[Hi guys,<br /><br />I don't know if its possible, but i'd like to create an automation for spam response using OSSIM. I use Request Tracker for Incident Response Teams (Best Practice's RTIR) to receive abuse messages and report to our local spam team. Do you have expectations to integrate OSSIM and RTIR (as a plugin or adding its features in OSSIM) in a near future?<br /><br />Thanks<br />]]></description>
   </item>
   <item>
      <title>Is there a 32 bit versin of OSSIM?</title>
      <link>http://forums.alienvault.com/discussion/1282/is-there-a-32-bit-versin-of-ossim</link>
      <pubDate>Wed, 22 May 2013 10:35:37 +0000</pubDate>
      <category>Installation</category>
      <dc:creator>carwin</dc:creator>
      <guid isPermaLink="false">1282@/discussions</guid>
      <description><![CDATA[Is there a 32 bit versin of OSSIM?]]></description>
   </item>
   <item>
      <title>Clearing database</title>
      <link>http://forums.alienvault.com/discussion/920/clearing-database</link>
      <pubDate>Mon, 25 Feb 2013 14:34:27 +0000</pubDate>
      <category>SIEM / Console</category>
      <dc:creator>zoneranger</dc:creator>
      <guid isPermaLink="false">920@/discussions</guid>
      <description><![CDATA[Hello all<br /><br />I don't really want to rebuild my AlienVault box from scratch,<br />but the DB is quite full - especially after a mishap with sending too many Cisco events to it.<br /><br />Rather than use the web interface, is there a quick way of removing the following:<br /><br />- all of the hosts in the asset database<br />- all of the alarms<br />- potentially all of the event logs.<br /><br />Thanks!<br /><br />]]></description>
   </item>
   <item>
      <title>Alienvault Center is showing my sensor twice</title>
      <link>http://forums.alienvault.com/discussion/916/alienvault-center-is-showing-my-sensor-twice</link>
      <pubDate>Mon, 25 Feb 2013 10:27:12 +0000</pubDate>
      <category>Deployment Architecture</category>
      <dc:creator>derDuffy</dc:creator>
      <guid isPermaLink="false">916@/discussions</guid>
      <description><![CDATA[I'm pretty sure the questions was discussed before, but I can't find it in the forums anymore.<br /><br />My Alienvault Center is showing my sensor twice (see attached screenshot)<br /><br /><img src="http://www.raphael-otto.eu/share/center_error.JPG" height="258" width="888" alt="image" /><br /><br />How can I get rid of that and how can I prevent it form happening again ?<br /><br />Thanks in advance!<br /><br />]]></description>
   </item>
   <item>
      <title>how to solve this ??? ossec analysisd testing rules failed. configuration error. exiting</title>
      <link>http://forums.alienvault.com/discussion/1285/how-to-solve-this-ossec-analysisd-testing-rules-failed-configuration-error-exiting</link>
      <pubDate>Thu, 23 May 2013 06:15:41 +0000</pubDate>
      <category>Configuring data sources</category>
      <dc:creator>IRFAN</dc:creator>
      <guid isPermaLink="false">1285@/discussions</guid>
      <description><![CDATA[<span><span>Hi Everyone !</span></span><div>I am quite new to ossim need some help.<br /><br />I am interested to get logs from a windows machine on ossim(all in one) via ossec.I have two Virtual machines properly communicating with each other.<br />I had successfully configured both ossec on ossim side and ossec agent manager on windows side. Now after doing all configurations I do this:<br /># cd /var/ossec/bin/</div><div># ./ossec-control stop<br />#&nbsp;<span>./ossec-control start</span></div><div><span><br /></span></div><div><span>After last command I got this :&nbsp;</span><span><span>OSSEC analysisd: Testing rules failed. Configuration error. Exiting.<br /><br />Waiting for asap response!</span></span></div><div><span><span>Thanks&nbsp;</span></span></div>]]></description>
   </item>
   <item>
      <title>No SIEM events from Juniper-SRX plugin after Upgrade 4.2</title>
      <link>http://forums.alienvault.com/discussion/1250/no-siem-events-from-juniper-srx-plugin-after-upgrade-4-2</link>
      <pubDate>Wed, 15 May 2013 07:34:06 +0000</pubDate>
      <category>SIEM / Console</category>
      <dc:creator>infosecq</dc:creator>
      <guid isPermaLink="false">1250@/discussions</guid>
      <description><![CDATA[After upgrading to 4.2. SIEM events dashboard not showing any data from source juniper-srx plugin. I tried to access SFTP through WinScp, connection refused. Can login through SSH and tail to check log reception which shows. But nothing on SIEM page. <br />Can anyone assist me on this issue.<br /><br />Thanks<br />]]></description>
   </item>
   </channel>
</rss>