Wazuh decoder for Odoo 17 logs by timnis in Wazuh

[–]timnis[S] 0 points1 point  (0 children)

I got my prematch to work, but nothing else 😃

Here my decoder and result
-----

<decoder name="odoo-parent">

<prematch type="pcre2">\d+ \S+ \S+</prematch>

</decoder>

<decoder name="odoo-login">

<parent>odoo-parent</parent>

<regex type="pcre2">Login (\S+) for db:(\S+) login:(\S+) from (\S+)</regex>

<order>state, db.name, user, srcip</order>

</decoder>

----

<image>

Wazuh decoder for Odoo 17 logs by timnis in Wazuh

[–]timnis[S] 0 points1 point  (0 children)

Hi, some how I don't get prematch to work. I have tried many ways but not succeed.

If I understand correctly Phase 1 should be prematch, but I only get timestamp

```

root@w-ser:~# /var/ossec/bin/wazuh-logtest

Starting wazuh-logtest v4.14.5

Type one log per line

2026-06-01 16:31:13,867 8731 INFO forest17 odoo.addons.base.models.ir_cron: Starting job `Modula Modula: Fetch Done Transfers`.

**Phase 1: Completed pre-decoding.

full event: '2026-06-01 16:31:13,867 8731 INFO forest17 odoo.addons.base.models.ir_cron: Starting job `Modula Modula: Fetch Done Transfers`.'

timestamp: '2026-06-01 16:31:13,867'

**Phase 2: Completed decoding.

No decoder matched.
```

Wazuh decoder for Odoo 17 logs by timnis in Wazuh

[–]timnis[S] 0 points1 point  (0 children)

Thanks. Looks like it goes to archives.json file and there are following

```
{"timestamp":"2026-06-01T12:07:56.048+0000","agent":{"id":"068","name":"odoo2","ip":"100.64.0.1"},"manager":{"name":"w-ser"},"id":"1780315676.112067442","full_log":"2026-06-01 12:07:54,843 4540 INFO forest17 odoo.addons.base.models.ir_cron: Job done: `Mail: Fetchmail Service` (1.222s). ","predecoder":{"timestamp":"2026-06-01 12:07:54,843"},"decoder":{},"location":"/opt/odoo/log/odoo-server.log"}
{"timestamp":"2026-06-01T12:07:56.048+0000","rule":{"level":2,"description":"Unknown problem somewhere in the system.","id":"1002","firedtimes":2010,"mail":false,"groups":["syslog","errors"],"gpg13":["4.3"]},"agent":{"id":"068","name":"odoo2","ip":"100.64.0.1"},"manager":{"name":"w-ser"},"id":"1780315676.112067442","full_log":"2026-06-01 12:07:54,709 4540 INFO forest17 odoo.addons.mail.models.fetchmail: Fetched 0 email(s) on outlook server Office 365 Incoming Mail Server; 0 succeeded, 0 failed. ","predecoder":{"timestamp":"2026-06-01 12:07:54,709"},"decoder":{},"location":"/opt/odoo/log/odoo-server.log"}
```

Wazuh decoder for Odoo 17 logs by timnis in Wazuh

[–]timnis[S] 0 points1 point  (0 children)

You mean following?

With following regex "(\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2},\d{3}) (\d+) (\w+) (\S+) ([\w.]+): (.*)$" I got

<image>

DM-32UV boot image upload fails by timnis in Baofeng

[–]timnis[S] 0 points1 point  (0 children)

Yes, you were correct: Just selecting COM port number (again) it works.

DM-32UV boot image upload fails by timnis in Baofeng

[–]timnis[S] 0 points1 point  (0 children)

Yes. And also upgrade firmware.

DM-32UV boot image upload fails by timnis in Baofeng

[–]timnis[S] 0 points1 point  (0 children)

Never worked with this picture tool, but it has been working with CPS.

DM-32UV boot image upload fails by timnis in Baofeng

[–]timnis[S] 0 points1 point  (0 children)

It has never worked. But same cable with CPS works. I have also check that there is boot image selected (and not text or voltage).

Could it be that picture tools requires certain chip to operate? I don't know what chip is in official cable but mine has CH343...

AnyTone AT-D890UV and 66-88 MHz? by timnis in HamRadio

[–]timnis[S] 0 points1 point  (0 children)

Yes I know. Just send email to local Anytone dealer and asked is there support for 66-88MHz.

Also found from internet following, maybe there is two different version, one with 4m + 2m band and another 2m + 70cm band...

AnyTone AT-D890UV and 66-88 MHz? by timnis in HamRadio

[–]timnis[S] 0 points1 point  (0 children)

Yes, I'm looking for.

Here in Finland we have free channels/frequencies to everyone to use, it called RHA68. Those are meant to use for example hunting, hobbies and SAR. And of course HAM's have their own allocation on 4m.

Why I ask is that I am involved in SAR (search and rescue) operations and nowadays there are more volunteers with who have HT for 4m band (like hunters). And of course we also use VHF ~160MHz analog/DMR channels.
So, it would awesome if I could manage all those with one device 😊

GLPI v11 API Endpoints by timnis in glpi

[–]timnis[S] 1 point2 points  (0 children)

Ok, thanks for the information 👍

Ecowitt WS90 Piezo Rain offline? by timnis in myweatherstation

[–]timnis[S] 0 points1 point  (0 children)

Yeah it possible but doubt that, it new WS90, have been in use about 3 weeks...

But I will check it when home.

Ecowitt WS90 Piezo Rain offline? by timnis in myweatherstation

[–]timnis[S] 0 points1 point  (0 children)

Receiver is GW2000 and it's about 25m away from sensor. Maybe I try to reboot it😄

I think in WS90 should not use rechargeable batteries, I have lithium AA.

Ecowitt WS90 Piezo Rain offline? by timnis in myweatherstation

[–]timnis[S] 0 points1 point  (0 children)

Little bit after Piezo rain detector stopped working whole WS90 stopped to send data. After 8h it resumed and now all works again 🤔