|
Thanks for the clarification on what to type. Now, where do I type it? Which file gets the commands you document below.
Also, how frequently will the referenced files get parsed by OSSEC?
Unfortunately the reverse proxy we use (Novell iChain) does not support SYSLOG, only FTP.
John R. McKean Sr. Systems Security Administrator Oregon State Lottery (503) 540-1462 >>>[EMAIL PROTECTED] 10/02/06 12:45 pm >>> ... You will need to add a "localfile" entry for each log file. Something like: <localfile> <log_format>syslog</log_format> <location>/var/log/proxyftp/domain1</location> </localfile> <localfile> <log_format>syslog</log_format> <location>/var/log/proxyftp/domain1</location> </localfile> But try to check if your proxy server does not support remote syslog or that you can not really install an agent on it... |
- [ossec-list] Newbie needs configuration help John McKean
- [ossec-list] Re: Newbie needs configuration help Daniel Cid
- [ossec-list] Newbie needs configuration help John McKean
- [ossec-list] Newbie needs configuration help John McKean
- [ossec-list] Newbie needs configuration help John McKean
- [ossec-list] Re: Newbie needs configuration help Kalevi Nyman
- [ossec-list] Newbie needs configuration help John McKean
