small question :) how to deal with rules where source address is set like daniel mentioned? like fw rules / apache rules / ssh rules etc ...
is it possible to only set it to the "host" address if it's not set via rules? and what about multi homed "server"? a set to the host address (ossec address) would alert attacks/events to the wrong interface this could lead to wrong correlation. and by the way ossec is not only a hid it's a very good lid ;) and that's here the problem *g* just my 2 cent cheers philipp
