Hi Dan, The best way to get started is by using this document: http://www.ossec.net/ossec-docs/conf2007-dcid.pdf
Also, if you can share your logs with us, we can certainly help you adding support for them. Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On Thu, Aug 28, 2008 at 2:14 PM, <[EMAIL PROTECTED]> wrote: > > Greetings, > > I would like to write some rules to monitor syslog and the ems log files > on HP-UX (older versions) > > Is there a document that covers the guidelines/syntax of rule creation? > > > thanks > > ----------------------------------------- > Notice: The information contained in this electronic mail > transmission is intended by The J.M. Smucker Company (or one of its > subsidiaries) for the sole use of the named individual or entity to > which it is directed and may contain information that is privileged > or otherwise confidential. If you have received this electronic > mail transmission in error, please notify the sender of the error > by reply email so that our address record can be corrected. Thank > you. >
