Re: [Prelude Universal SIM system] #313: Configuration PRELUDE-LML WITH PRELUDE-MANAGER
"Prelude Universal SIM system" <[email protected]> Tue, 16 Sep 2008 15:07:12 -0000
| Newsgroups | gmane.comp.security.ids.prelude.devel |
|---|---|
| Message-ID | <[email protected]> |
#313: Configuration PRELUDE-LML WITH PRELUDE-MANAGER -----------------------------------+---------------------------------------- Reporter: [email protected] | Owner: Type: task | Status: new Priority: normal | Milestone: Prelude-LML 0.9.14 Component: prelude-lml | Version: 0.9 Severity: normal | Resolution: Keywords: | -----------------------------------+---------------------------------------- Description changed by yoann: Old description: > Hi Partners, > Actually, i had install Prelude-LML and registrer the sensor Prelude-LML > in the Prelude-Manager. I can see the agent (Sensor) in the Prelude > Manager but i can´t see any alert o event. > > Please, can you help me to configurate the Prelude-lml? > CLIENT.CONF PRELUDE-LML.CONF > > I want send the events to Prelude Manager by SYSLOG PORT 514 UDP. > When I uncomment the line udp-server and add the IP Console an restart > the service prelude-lml (/etc/init.d/prelude-lml stop) (/etc/init.d > /prelude-lml start) > > [format=metalog] > prefix-regex = "^(?P<timestamp>.{15}) \[(?P<program>\S+)\] " > time-format = "%b %d %H:%M:%S" > file = /var/log/everything/current > udp-server = x.x.x.x > > OR > > include = /etc/prelude/default/idmef-client.conf > > # Address where the Prelude Manager Server is listening on. > # if value is "127.0.0.1", the connection will occur throught > # an UNIX socket. > # > # This entry is disabled. The default is to use the entry > # located in the Prelude system wide clients.conf. You may > # overwrite the default address for this sensor by uncommenting > # this entry. > # > server-addr = x.x.x.x > > This show the following message error: > > udp_server_new:199: couldn´t bind to socket: Cannot assign requested > address > > Can you help me for solvent this problem? > > Best Regards, > Álvaro Quispe New description: Hi Partners, Actually, i had install Prelude-LML and registrer the sensor Prelude-LML in the Prelude-Manager. I can see the agent (Sensor) in the Prelude Manager but i can´t see any alert o event. Please, can you help me to configurate the Prelude-lml? CLIENT.CONF PRELUDE-LML.CONF I want send the events to Prelude Manager by SYSLOG PORT 514 UDP. When I uncomment the line udp-server and add the IP Console an restart the service prelude-lml (/etc/init.d/prelude-lml stop) (/etc/init.d /prelude-lml start) {{{ [format=metalog] prefix-regex = "^(?P<timestamp>.{15}) \[(?P<program>\S+)\] " time-format = "%b %d %H:%M:%S" file = /var/log/everything/current udp-server = x.x.x.x }}} OR include = /etc/prelude/default/idmef-client.conf # Address where the Prelude Manager Server is listening on. # if value is "127.0.0.1", the connection will occur throught # an UNIX socket. # # This entry is disabled. The default is to use the entry # located in the Prelude system wide clients.conf. You may # overwrite the default address for this sensor by uncommenting # this entry. # server-addr = x.x.x.x This show the following message error: {{{ udp_server_new:199: couldn´t bind to socket: Cannot assign requested address }}} Can you help me for solvent this problem? Best Regards, Álvaro Quispe -- -- Ticket URL: <https://trac.prelude-ids.org/ticket/313#comment:1> Prelude Universal SIM system <http://www.prelude-ids.com> Prelude Universal SIM system _______________________________________________ Prelude-devel site list [email protected] http://lists.prelude-ids.org/mailman/listinfo/prelude-devel