Hi Matthias,

Unfortunately, you can't disable it on version 1.5.1, but I added a
config flag for 1.6 to allow
you to do that. If you update your server (ossec manager) to the
following snapshot:

http://www.ossec.net/files/snapshots/ossec-hids-080818.tar.gz


You can edit the internal_options.conf and set "analysisd.log_fw" to
zero to disable it.

*actually, you can now create local_internal_options.conf and set it in there.


Thanks,

--
Daniel B. Cid
dcid ( at ) ossec.net



On Tue, Aug 12, 2008 at 6:29 AM, Matthias Schmidt <[EMAIL PROTECTED]> wrote:
>
> Hi List!
>
> On some of our machines, ipmon logs every connection to the authlog.
> (I am not allowed to change this, unfortunately.) OSSEC logs all this
> stuff to the firewall.log. This results in ~1,5 GB OSSEC firewall-logs
> per day.
> Is there a possiblity to deactivate or configure the firewall.log? I'm
> also not sure what the sense of the firewall.log is. Why do we need
> it?
>
> Thanks & Regards,
> Matthias
>

Reply via email to