I have that come up as well, even though I have it set to be ignored (in the ossec.conf file): <ignore>/dev/shm</ignore>
OSSEC HIDS Notification. 2008 Sep 09 13:19:19 Received From: scrambles->rootcheck Rule: 510 fired (level 7) -> "Host-based anomaly detection event (rootcheck)." Portion of the log(s): File '/dev/shm/pulse-shm-3847568897' present on /dev. Possible hidden file. --END OF NOTIFICATION Do I have the <ignore> line incorrect perhaps? -Chuck (MdMonk) On Tue, Sep 9, 2008 at 12:09 PM, Martin West <[EMAIL PROTECTED]> wrote: > > Sorry need new glasses, Im running 1.6 > > On Tue, 2008-09-09 at 19:06 +0100, Martin West wrote: >> This shared memory I assume and not something to be alarmed at. >> >> Received From: lenovo3->rootcheck >> Rule: 510 fired (level 7) -> "Host-based anomaly detection event >> (rootcheck)." >> Portion of the log(s): >> >> File '/dev/shm/pulse-shm-3257873433' present on /dev. Possible hidden >> file. >> >> System is ubuntu desktop 8.04 updated >> ossec is 1.5 but I see there is a 1.6 - will install shortly >> >> Thanks Martin > -- > regards > Martin West > 07879 680096 > skype:amartinwest > >
