Thanks for the clarification on what to type. Now, where do I type it? Which file gets the commands you document below.
 
Also, how frequently will the referenced files get parsed by OSSEC?
 
Unfortunately the reverse proxy we use (Novell iChain) does not support SYSLOG, only FTP.


John R. McKean
Sr. Systems Security Administrator
Oregon State Lottery
(503) 540-1462

>>>[EMAIL PROTECTED] 10/02/06 12:45 pm >>>

...

You will need to add a "localfile" entry for each log file. Something like:

<localfile>
 <log_format>syslog</log_format>
 <location>/var/log/proxyftp/domain1</location>
</localfile>

<localfile>
 <log_format>syslog</log_format>
 <location>/var/log/proxyftp/domain1</location>
</localfile>

But try to check if your proxy server does not support remote syslog
or that you can not really install an agent on it...

Reply via email to