[ossec-list] "eventlog" and "eventchannel". What is difference?

2016-09-14 Thread Duẩn Phạm
What is difference between "eventlog" and "eventchannel" in ossec.conf (Agent)? Application eventlog & Application eventchannel -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and

[ossec-list] Re: Filter Windows Event Log at client

2016-03-29 Thread Duẩn Phạm
I used *or* and it worked. Thanks very much! -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to ossec-list+unsubscr...@googlegroups.com. For more options,

[ossec-list] Re: Filter Windows Event Log at client

2016-03-29 Thread Duẩn Phạm
Jesus Linares. > > On Monday, March 28, 2016 at 10:58:57 AM UTC+2, Duẩn Phạm wrote: >> >> Hi, >> >> I have installed the new version of OSSEC v2.8.3. I have a windows ossec >> client. I would like to filter Windows event logs >> (Applications/Securit

[ossec-list] Filter Windows Event Log at client

2016-03-28 Thread Duẩn Phạm
Hi, I have installed the new version of OSSEC v2.8.3. I have a windows ossec client. I would like to filter Windows event logs (Applications/Security/System/Application and Services Log) based on the event ids at ossec client (in order to reduce the logs forwarded to OSSEC manager). Ex: