[ossec-list] Simple(?) - Forensics (historical?) but live

2012-06-29 Thread Kat
Here's hoping there is a simple answer to this. I know of the technique to run the forensics into ossec-logtest. And that is a fabulous tool/method. But, I want to take a previous years data - BO - (before ossec) and run it through and have ossec actually process it into the appropriate log

Re: [ossec-list] Simple(?) - Forensics (historical?) but live

2012-06-29 Thread Frank Stefan Sundberg Solli
Hi, You can try to pipe the data into ossec's syslog daemon with cat and netcat On Fri, Jun 29, 2012 at 7:07 PM, Kat uncommon...@gmail.com wrote: Here's hoping there is a simple answer to this. I know of the technique to run the forensics into ossec-logtest. And that is a fabulous