I've been trying to get ossec work with netscreen logs. I'm unable to figure
out why only device name ns5gt works.
Replacing that name with any other valid device name in decoder.xml doesn't
produce any records in firewall.log
I also tried completely removing program_name and just leaving prematch, it
still doesn't produce any entries in firewall.log
I'd appreciate any suggestions anyone may have.
Tom

Reply via email to