Just to make sure that we're all on the same page.

Source IP should be set to the IP address of the remote host that is 
generating the event. Target IP should be sent to the IP address of the 
agent.

I realize that is obvious.

Regards,
        Adriel T. Desautels
        Chief Technology Officer
        Netragard, LLC.
        Office : 617-934-0269
        Mobile : 617-633-3821
        http://www.linkedin.com/pub/1/118/a45

        Join the Netragard, LLC. Linked In Group:
        http://www.linkedin.com/e/gis/48683/0B98E1705142

---------------------------------------------------------------
Netragard, LLC - http://www.netragard.com  -  "We make IT Safe"
Penetration Testing, Vulnerability Assessments, Website Security

Netragard Whitepaper Downloads:
-------------------------------
Choosing the right provider : http://tinyurl.com/2ahk3j
Three Things you must know  : http://tinyurl.com/26pjsn


Sebastien Tricaud wrote:
>     | Daniel,
>     |         I think thats a logical solution. Since OSSEC is an HIDS and 
> not a
>     | NIDS, using the IP of the HIDS would be ideal. That would enable prelude
>     | to correlate events better.
>     |
> 
> I totally agree.
> 
> 
begin:vcard
fn:Adriel T Desautels
n:Desautels;Adriel T
org:Netragard, LLC.
adr:;;17 Sheldon Road;Mendham ;NJ;;USA
email;internet:[EMAIL PROTECTED]
title:Chief Technology Officer
tel;work:617-934-0269
tel;cell:617-633-3821
x-mozilla-html:FALSE
url:http://www.netragard.com
version:2.1
end:vcard

Reply via email to