Bummi
2018-10-25 19:41:47 UTC
Hello!
I am not getting daily reports emailed to me. Regular email alerts seems to work just fine.
Here is my current configuration:
<alerts>
<log_alert_level>2</log_alert_level>
<email_alert_level>10</email_alert_level>
</alerts>
<reports>
<level>10</level>
<title>Daily report: Alerts with level higher than 10</title>
<email_to>***@mymail.com</email_to>
<group>syscheck</group>
<title>Daily report: File changes</title>
<email_to>***@mymail.com</email_to>
<rule>554</rule>
<title>Daily report: File added to system</title>
<email_to>***@mymail.com</email_to>
</reports>
I see this in my ossec-monitord logs for the level 10 report but nothing for the SYSCHECK or 554 report. I don't have any alerts higher than level 10 so I understand that this particular report will not be sent.
2018-10-25 00:00:16 | ossec-monitord | info | Report 'Daily report: Alerts with level higher than 10' completed and zero alerts post-filter.
2018-10-25 00:00:16 | ossec-monitord | info | Report 'Daily report: Alerts with level higher than 10' empty.
2018-10-25 00:00:11 | ossec-monitord | info | Starting new log after rotation.
2018-10-25 00:00:11 | ossec-monitord | info | Starting daily reporting for 'Daily report: Alerts with level higher than 10'
I understand that reports run at midnight. Is there a way to force run them for testing purposes?
Thanks,
-r
I am not getting daily reports emailed to me. Regular email alerts seems to work just fine.
Here is my current configuration:
<alerts>
<log_alert_level>2</log_alert_level>
<email_alert_level>10</email_alert_level>
</alerts>
<reports>
<level>10</level>
<title>Daily report: Alerts with level higher than 10</title>
<email_to>***@mymail.com</email_to>
<group>syscheck</group>
<title>Daily report: File changes</title>
<email_to>***@mymail.com</email_to>
<rule>554</rule>
<title>Daily report: File added to system</title>
<email_to>***@mymail.com</email_to>
</reports>
I see this in my ossec-monitord logs for the level 10 report but nothing for the SYSCHECK or 554 report. I don't have any alerts higher than level 10 so I understand that this particular report will not be sent.
2018-10-25 00:00:16 | ossec-monitord | info | Report 'Daily report: Alerts with level higher than 10' completed and zero alerts post-filter.
2018-10-25 00:00:16 | ossec-monitord | info | Report 'Daily report: Alerts with level higher than 10' empty.
2018-10-25 00:00:11 | ossec-monitord | info | Starting new log after rotation.
2018-10-25 00:00:11 | ossec-monitord | info | Starting daily reporting for 'Daily report: Alerts with level higher than 10'
I understand that reports run at midnight. Is there a way to force run them for testing purposes?
Thanks,
-r
--
---
You received this message because you are subscribed to the Google Groups "ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ossec-list+***@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
---
You received this message because you are subscribed to the Google Groups "ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ossec-list+***@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.