- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: HIDS Alert Log Format
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-26-2007 06:50 AM
03-26-2007 06:50 AM
We just installed HIDS 4.0 agent on some clients. All is working well except for the format of the alert logs. It seems as though there are control characters in the alert logs and the format is very much of as far as the legibility. Could anyone tell us why we may be seeing this? I'll attach a sample of one of our alert.log files.
Thanks in advance.....
KPS
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-26-2007 06:55 AM
03-26-2007 06:55 AM
Re: HIDS Alert Log Format
Thanks,
KPS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-26-2007 07:48 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-26-2007 08:22 AM
03-26-2007 08:22 AM
Re: HIDS Alert Log Format
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-27-2007 11:11 AM
03-27-2007 11:11 AM
Re: HIDS Alert Log Format
The alert.log file on each agent was not designed for viewing but is instead a persistent alert respository on each agent in case the admin GUI/CLUI ever needs to retrieve those alerts for viewing. HIDS v4.0 and prior versions require that you use the admin GUI or CLUI to view formatted alerts.
HIDS v4.1 (to be released soon this spring) has a new alert reporting command-line feature that allows you to generate consolidated alert reports across any number of agents. The reports can be generated in HTML, text, or "raw" format. For the "raw" formatted reports, the delimiter character can be configured to be any character. Raw reports facilitates post-processing of alerts by customized scripts that you write, much like the alert response programs allow you to do post-processing of alerts in near real-time. Both the content and the presentation of the HTML and text formatted reports are configurable and, using cron, you can have incremental reports sent periodically to specified email addresses.
HIDS v4.1 will also come with a useful tool for fine tuning schedules by presenting consolidated alerts reports and generating the corresponding filtering rules for those alerts you deem safe to ignore.
HIDS v4.1 also contains a new feature for proactively suppressing duplicate alerts.
A list of new features and benefits will be available in the Release Notes when V4.1 is released.
Pierre