I get that too (ubuntu 8.04). Don't know the answer. In case you didn't see
it, here's a recent thread on the subject:

'[ossec-list] Re: shm hidden file alert' - MARC
http://marc.info/?l=ossec-list&m=122099254509051&w=2

-Eric

On Wed, Nov 5, 2008 at 2:31 PM, Kayvan A. Sylvan <[EMAIL PROTECTED]> wrote:

>
> I get these alerts:
>
> Received From: satyr->rootcheck
> Rule: 510 fired (level 7) -> "Host-based anomaly detection event
> (rootcheck)."
> Portion of the log(s):
>
> File '/dev/shm/pulse-shm-43637809' present on /dev. Possible hidden file.
>
> How do I cause OSSEC not to send an alert for /dev/shm/pulse-shm-\d+ ?
>
> Thanks for any replies.
>
> Best regards,
>
> ---Kayvan
>

Reply via email to