I have that come up as well, even though I have it set to be ignored
(in the ossec.conf file):   <ignore>/dev/shm</ignore>

OSSEC HIDS Notification.
2008 Sep 09 13:19:19

Received From: scrambles->rootcheck
Rule: 510 fired (level 7) -> "Host-based anomaly detection event (rootcheck)."
Portion of the log(s):

File '/dev/shm/pulse-shm-3847568897' present on /dev. Possible hidden file.


 --END OF NOTIFICATION

Do I have the <ignore> line incorrect perhaps?

-Chuck (MdMonk)

On Tue, Sep 9, 2008 at 12:09 PM, Martin West <[EMAIL PROTECTED]> wrote:
>
> Sorry need new glasses, Im running 1.6
>
> On Tue, 2008-09-09 at 19:06 +0100, Martin West wrote:
>> This shared memory I assume and not something to be alarmed at.
>>
>> Received From: lenovo3->rootcheck
>> Rule: 510 fired (level 7) -> "Host-based anomaly detection event
>> (rootcheck)."
>> Portion of the log(s):
>>
>> File '/dev/shm/pulse-shm-3257873433' present on /dev. Possible hidden
>> file.
>>
>> System is ubuntu desktop 8.04 updated
>> ossec is 1.5 but I see there is a 1.6 - will install shortly
>>
>> Thanks Martin
> --
> regards
>   Martin West
>   07879 680096
>   skype:amartinwest
>
>

Reply via email to