You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I stumbled upon this error when debugging a configuration problem with ossec-logtest where a rule was missing the if_sid which seems to be absolutely necessary and stops the whole ossec setup from working in that instance. Documentation is lacking as well regarding if_sid but the most useful thing would be to improve logging output imho - and not only in the logtest application because one has to find out about this first. I completely unnecessarily wasted several hours due to this problem. This report is also food for search engines.
I still have to use v3.6.0 but from the looks of it the respective message is still the same in HEAD as it has not changed since 2015.
The text was updated successfully, but these errors were encountered:
No. It was not supposed to be a normal rule, and apparently it was not a complete "regular rules" either, because... then it would not have wrecked havoc as described in the OP.
I stumbled upon this error when debugging a configuration problem with
ossec-logtest
where a rule was missing theif_sid
which seems to be absolutely necessary and stops the whole ossec setup from working in that instance. Documentation is lacking as well regardingif_sid
but the most useful thing would be to improve logging output imho - and not only in the logtest application because one has to find out about this first. I completely unnecessarily wasted several hours due to this problem. This report is also food for search engines.I still have to use v3.6.0 but from the looks of it the respective message is still the same in HEAD as it has not changed since 2015.
The text was updated successfully, but these errors were encountered: