Hi Matthias, Unfortunately, you can't disable it on version 1.5.1, but I added a config flag for 1.6 to allow you to do that. If you update your server (ossec manager) to the following snapshot:
http://www.ossec.net/files/snapshots/ossec-hids-080818.tar.gz You can edit the internal_options.conf and set "analysisd.log_fw" to zero to disable it. *actually, you can now create local_internal_options.conf and set it in there. Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On Tue, Aug 12, 2008 at 6:29 AM, Matthias Schmidt <[EMAIL PROTECTED]> wrote: > > Hi List! > > On some of our machines, ipmon logs every connection to the authlog. > (I am not allowed to change this, unfortunately.) OSSEC logs all this > stuff to the firewall.log. This results in ~1,5 GB OSSEC firewall-logs > per day. > Is there a possiblity to deactivate or configure the firewall.log? I'm > also not sure what the sense of the firewall.log is. Why do we need > it? > > Thanks & Regards, > Matthias >
