Hi Peter, I agree with Jeff. If you can send some logs to us, we can definitely write some rules/decoders for it.
We only have a few samples: http://www.ossec.net/wiki/index.php/Log_Samples_Sonicwall But with a few more we can easily add support for it. *btw, if you prefer, you can send to me privately to avoid having to remove ip addresses, etc. Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On 8/18/07, Jeff Schroeder <[EMAIL PROTECTED]> wrote: > > On Aug 17, 8:18 pm, "Peter M. Abraham" <[EMAIL PROTECTED]> > wrote: > > Does anyone have any rules they have, and are willing to share in > > terms of monitoring SonicWall Pro series firewalls? > > If you could paste some log lines, it probably wouldn't take much to > write decoders for it. Once decoders are written that work, they can > be included with the next version of ossec. > >
