Hi Adriel, Can you try the following snapshot:
http://www.ossec.net/files/snapshots/ossec-hids-080428.tar.gz It has the fix for the prelude output that we discussed. Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On Fri, Apr 25, 2008 at 11:37 AM, Adriel Desautels <[EMAIL PROTECTED]> wrote: > Just to make sure that we're all on the same page. > > Source IP should be set to the IP address of the remote host that is > generating the event. Target IP should be sent to the IP address of the > agent. > > I realize that is obvious. > > > Regards, > Adriel T. Desautels > Chief Technology Officer > Netragard, LLC. > Office : 617-934-0269 > Mobile : 617-633-3821 > http://www.linkedin.com/pub/1/118/a45 > > Join the Netragard, LLC. Linked In Group: > http://www.linkedin.com/e/gis/48683/0B98E1705142 > > --------------------------------------------------------------- > Netragard, LLC - http://www.netragard.com - "We make IT Safe" > Penetration Testing, Vulnerability Assessments, Website Security > > Netragard Whitepaper Downloads: > ------------------------------- > Choosing the right provider : http://tinyurl.com/2ahk3j > Three Things you must know : http://tinyurl.com/26pjsn > > > Sebastien Tricaud wrote: > > > > | Daniel, > > | I think thats a logical solution. Since OSSEC is an HIDS and > not a > > | NIDS, using the IP of the HIDS would be ideal. That would enable > prelude > > | to correlate events better. > > | > > > > I totally agree. > > > > >
