Hi Adriel,

Can you try the following snapshot:

http://www.ossec.net/files/snapshots/ossec-hids-080428.tar.gz

It has the fix for the prelude output that we discussed.


Thanks,

--
Daniel B. Cid
dcid ( at ) ossec.net

On Fri, Apr 25, 2008 at 11:37 AM, Adriel Desautels <[EMAIL PROTECTED]> wrote:
> Just to make sure that we're all on the same page.
>
>  Source IP should be set to the IP address of the remote host that is
>  generating the event. Target IP should be sent to the IP address of the
>  agent.
>
>  I realize that is obvious.
>
>
>  Regards,
>         Adriel T. Desautels
>         Chief Technology Officer
>         Netragard, LLC.
>         Office : 617-934-0269
>         Mobile : 617-633-3821
>         http://www.linkedin.com/pub/1/118/a45
>
>         Join the Netragard, LLC. Linked In Group:
>         http://www.linkedin.com/e/gis/48683/0B98E1705142
>
>  ---------------------------------------------------------------
>  Netragard, LLC - http://www.netragard.com  -  "We make IT Safe"
>  Penetration Testing, Vulnerability Assessments, Website Security
>
>  Netragard Whitepaper Downloads:
>  -------------------------------
>  Choosing the right provider : http://tinyurl.com/2ahk3j
>  Three Things you must know  : http://tinyurl.com/26pjsn
>
>
>  Sebastien Tricaud wrote:
>
>
> >     | Daniel,
>  >     |         I think thats a logical solution. Since OSSEC is an HIDS and 
> not a
>  >     | NIDS, using the IP of the HIDS would be ideal. That would enable 
> prelude
>  >     | to correlate events better.
>  >     |
>  >
>  > I totally agree.
>  >
>  >
>

Reply via email to