Hello, On Thu, 6 Dec 2007 22:40:50 -0400 "Daniel Cid" <[EMAIL PROTECTED]> wrote:
> This level "100" alert is a bug that I just fixed at: > > http://www.ossec.net/files/snapshots/ossec-hids-071206.tar.gz Ok, level now is right. But even if I have the next in local_rules.xml: <rule id="3302" level="1" overwrite="yes"> <if_sid>3300</if_sid> <id>^550$</id> <description>Rejected by access list </description> <description>(Requested action not taken).</description> <group>spam,</group> </rule> and I see in alerts.log that it really have level="1", ossec still blocks IP's by rule 3302. Note, my active response configured to block from level 6 and higher. -- DSS5-RIPE DSS-RIPN mailto:[EMAIL PROTECTED] xmpp:[EMAIL PROTECTED] http://wizard.volgograd.ru/ 2:550/[EMAIL PROTECTED] 2:550/[EMAIL PROTECTED]
