Yes,
Worked beautiful. My only suggestion would be to insert the agent IP as
the source AND target IP for file system integrity change alerts. Those
are the last series of alerts that are not correlating due to missing IP
information.
Short of that... very nice work!
Regards,
Adriel T. Desautels
Chief Technology Officer
Netragard, LLC.
Office : 617-934-0269
Mobile : 617-633-3821
http://www.linkedin.com/pub/1/118/a45
Join the Netragard, LLC. Linked In Group:
http://www.linkedin.com/e/gis/48683/0B98E1705142
---------------------------------------------------------------
Netragard, LLC - http://www.netragard.com - "We make IT Safe"
Penetration Testing, Vulnerability Assessments, Website Security
Netragard Whitepaper Downloads:
-------------------------------
Choosing the right provider : http://tinyurl.com/2ahk3j
Three Things you must know : http://tinyurl.com/26pjsn
Sebastien Tricaud wrote:
> Hello Daniel,
>
> |
> | http://www.ossec.net/files/snapshots/ossec-hids-080428.tar.gz
> |
> | It has the fix for the prelude output that we discussed.
> |
>
> I just tried this one and it works as expected.
>
> Thanks!
> Sebastien.
>
>
begin:vcard
fn:Adriel T Desautels
n:Desautels;Adriel T
org:Netragard, LLC.
adr:;;17 Sheldon Road;Mendham ;NJ;;USA
email;internet:[EMAIL PROTECTED]
title:Chief Technology Officer
tel;work:617-934-0269
tel;cell:617-633-3821
x-mozilla-html:FALSE
url:http://www.netragard.com
version:2.1
end:vcard