<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-7652481.post6777771618290011673..comments</id><updated>2011-05-19T20:01:46.723-04:00</updated><category term='MySQL'/><category term='Tor'/><category term='NSM'/><category term='dns'/><category term='Snort'/><category term='book review'/><category term='Sguil'/><category term='apt'/><category term='hacking'/><category term='Perl'/><category term='Events'/><category term='WTF?'/><category term='OSSEC'/><category term='management'/><title type='text'>Comments on Infosec Potpourri: Switching to Sguil:  A whole new meaning</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.vorant.com/feeds/6777771618290011673/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/6777771618290011673/comments/default'/><link rel='alternate' type='text/html' href='http://blog.vorant.com/2008/03/switching-to-sguil-whole-new-meaning.html'/><author><name>David Bianco</name><uri>http://www.blogger.com/profile/09760835714791462863</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>1</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7652481.post-7780726888136905469</id><published>2011-05-19T20:01:46.723-04:00</published><updated>2011-05-19T20:01:46.723-04:00</updated><title type='text'>Hi,
I have installed sguil and have an installatio...</title><content type='html'>Hi,&lt;br /&gt;I have installed sguil and have an installation of ossec. I&amp;#39;m trying the ossec_agent.tcl in order to see ossec alerts on sguil, but I&amp;#39;m getting an error message. Can you give me a clue?&lt;br /&gt;--------------------------&lt;br /&gt;wrong # args: should be &amp;quot;regsub ?switches? exp string subSpec varName&amp;quot;&lt;br /&gt;    while executing&lt;br /&gt;&amp;quot;regsub {(?x)&lt;br /&gt;        ^::ffff:&lt;br /&gt;   } $retVal &amp;quot;&amp;quot;&amp;quot;&lt;br /&gt;    (procedure &amp;quot;ResolveHostname&amp;quot; line 16)&lt;br /&gt;    invoked from within&lt;br /&gt;&amp;quot;ResolveHostname $agent&amp;quot;&lt;br /&gt;    (procedure &amp;quot;ProcessData&amp;quot; line 112)&lt;br /&gt;    invoked from within&lt;br /&gt;&amp;quot;ProcessData $line&amp;quot;&lt;br /&gt;    (procedure &amp;quot;ReadFile&amp;quot; line 13)&lt;br /&gt;    invoked from within&lt;br /&gt;&amp;quot;ReadFile $fileID&amp;quot;&lt;br /&gt;    (procedure &amp;quot;InitAgent&amp;quot; line 43)&lt;br /&gt;    invoked from within&lt;br /&gt;&amp;quot;InitAgent&amp;quot;&lt;br /&gt;    (file &amp;quot;./ossec_agent.tcl&amp;quot; line 684)&lt;br /&gt;-----------------------&lt;br /&gt;many thanks and keep the good work!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/6777771618290011673/comments/default/7780726888136905469'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7652481/6777771618290011673/comments/default/7780726888136905469'/><link rel='alternate' type='text/html' href='http://blog.vorant.com/2008/03/switching-to-sguil-whole-new-meaning.html?showComment=1305849706723#c7780726888136905469' title=''/><author><name>Oscar</name><uri>http://www.blogger.com/profile/07119001974118064457</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.vorant.com/2008/03/switching-to-sguil-whole-new-meaning.html' ref='tag:blogger.com,1999:blog-7652481.post-6777771618290011673' source='http://www.blogger.com/feeds/7652481/posts/default/6777771618290011673' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-679715442'/></entry></feed>
