I get that too (ubuntu 8.04). Don't know the answer. In case you didn't see it, here's a recent thread on the subject:
'[ossec-list] Re: shm hidden file alert' - MARC http://marc.info/?l=ossec-list&m=122099254509051&w=2 -Eric On Wed, Nov 5, 2008 at 2:31 PM, Kayvan A. Sylvan <[EMAIL PROTECTED]> wrote: > > I get these alerts: > > Received From: satyr->rootcheck > Rule: 510 fired (level 7) -> "Host-based anomaly detection event > (rootcheck)." > Portion of the log(s): > > File '/dev/shm/pulse-shm-43637809' present on /dev. Possible hidden file. > > How do I cause OSSEC not to send an alert for /dev/shm/pulse-shm-\d+ ? > > Thanks for any replies. > > Best regards, > > ---Kayvan >
