Hello,

On Thu, 6 Dec 2007 22:40:50 -0400
"Daniel Cid" <[EMAIL PROTECTED]> wrote:

> This level "100" alert is a bug that I just fixed at:
> 
> http://www.ossec.net/files/snapshots/ossec-hids-071206.tar.gz

Ok, level now is right. But even if I have the next in local_rules.xml:

  <rule id="3302" level="1" overwrite="yes">
    <if_sid>3300</if_sid>
    <id>^550$</id>
    <description>Rejected by access list </description>
    <description>(Requested action not taken).</description>
    <group>spam,</group>
  </rule>

and I see in alerts.log that it really have level="1", ossec still
blocks IP's by rule 3302. Note, my active response configured to block
from level 6 and higher.

-- 
DSS5-RIPE DSS-RIPN mailto:[EMAIL PROTECTED] xmpp:[EMAIL PROTECTED]
http://wizard.volgograd.ru/ 2:550/[EMAIL PROTECTED] 2:550/[EMAIL PROTECTED]

Reply via email to