Re: [Prelude Universal SIM system] #313: Configuration PRELUDE-LML WITH PRELUDE-MANAGER

"Prelude Universal SIM system" <[email protected]> Tue, 16 Sep 2008 15:07:12 -0000
Newsgroups gmane.comp.security.ids.prelude.devel
Message-ID <[email protected]>
#313: Configuration PRELUDE-LML WITH PRELUDE-MANAGER
-----------------------------------+----------------------------------------
 Reporter:  [email protected]  |        Owner:                    
     Type:  task                   |       Status:  new               
 Priority:  normal                 |    Milestone:  Prelude-LML 0.9.14
Component:  prelude-lml            |      Version:  0.9               
 Severity:  normal                 |   Resolution:                    
 Keywords:                         |  
-----------------------------------+----------------------------------------
Description changed by yoann:

Old description:

> Hi Partners,
> Actually, i had install Prelude-LML and registrer the sensor Prelude-LML
> in the Prelude-Manager. I can see the agent (Sensor) in the Prelude
> Manager but i can´t see any alert o event.
>
> Please, can you help me to configurate the Prelude-lml?
> CLIENT.CONF PRELUDE-LML.CONF
>
> I want send the events to Prelude Manager by SYSLOG PORT 514 UDP.
> When I uncomment the line udp-server and add the IP Console an restart
> the service prelude-lml (/etc/init.d/prelude-lml stop)    (/etc/init.d
> /prelude-lml start)
>
> [format=metalog]
> prefix-regex = "^(?P<timestamp>.{15}) \[(?P<program>\S+)\] "
> time-format = "%b %d %H:%M:%S"
> file = /var/log/everything/current
> udp-server = x.x.x.x
>
> OR
>
> include = /etc/prelude/default/idmef-client.conf
>

> # Address where the Prelude Manager Server is listening on.
> # if value is "127.0.0.1", the connection will occur throught
> # an UNIX socket.
> #
> # This entry is disabled. The default is to use the entry
> # located in the Prelude system wide clients.conf. You may
> # overwrite the default address for this sensor by uncommenting
> # this entry.
> #
> server-addr = x.x.x.x
>
> This show the following message error:
>
> udp_server_new:199: couldn´t bind to socket: Cannot assign requested
> address
>
> Can you help me for solvent this problem?
>
> Best Regards,
> Álvaro Quispe

New description:

 Hi Partners,
 Actually, i had install Prelude-LML and registrer the sensor Prelude-LML
 in the Prelude-Manager. I can see the agent (Sensor) in the Prelude
 Manager but i can´t see any alert o event.

 Please, can you help me to configurate the Prelude-lml?
 CLIENT.CONF PRELUDE-LML.CONF

 I want send the events to Prelude Manager by SYSLOG PORT 514 UDP.
 When I uncomment the line udp-server and add the IP Console an restart the
 service prelude-lml (/etc/init.d/prelude-lml stop)    (/etc/init.d
 /prelude-lml start)

 {{{
 [format=metalog]
 prefix-regex = "^(?P<timestamp>.{15}) \[(?P<program>\S+)\] "
 time-format = "%b %d %H:%M:%S"
 file = /var/log/everything/current
 udp-server = x.x.x.x
 }}}

 OR

 include = /etc/prelude/default/idmef-client.conf


 # Address where the Prelude Manager Server is listening on.
 # if value is "127.0.0.1", the connection will occur throught
 # an UNIX socket.
 #
 # This entry is disabled. The default is to use the entry
 # located in the Prelude system wide clients.conf. You may
 # overwrite the default address for this sensor by uncommenting
 # this entry.
 #
 server-addr = x.x.x.x

 This show the following message error:
 {{{
 udp_server_new:199: couldn´t bind to socket: Cannot assign requested
 address
 }}}

 Can you help me for solvent this problem?

 Best Regards,
 Álvaro Quispe

--

-- 
Ticket URL: <https://trac.prelude-ids.org/ticket/313#comment:1>
Prelude Universal SIM system <http://www.prelude-ids.com>
Prelude Universal SIM system
_______________________________________________
Prelude-devel site list
[email protected]
http://lists.prelude-ids.org/mailman/listinfo/prelude-devel