[ossec-list] Re: Ossec with ELK

2017-05-18 Thread alberto . rodriguez
Hello Akash Munjan In this link: https://documentation.wazuh.com/current/index.html you will find all the information related of Wazuh (an Ossec fork) and ELK integration. Let us know if you have any question. Best regards, On Thursday, May 18, 2017 at 5:22:39 PM UTC+2, Akash Munjal

[ossec-list] Re: Rule 510 is triggering events but logtest is not showing any rules that should be triggered

2017-05-18 Thread Gert Verhoog
Hi Jesus, I'm having the same problem, and the triggering of this rule causes so much noise that it's drowning out other alerts. I have added a rule like you suggested to my local rules: 510 /var/lib/docker/volumes/\.*/_data/\.* is owned by root and has written permissions to