Hi guys.
I just installed snort and tested it. Now I had the idea to combine it
with ossec. So I read a little bit in the wiki and saw that the rules
20300 - 20499 IDS (Snort specific)
are for snort. But I can't find them in the ossec/rules directory. I
used the latest stable version of ossec (ossec 2). Are there any rules
for the /var/log/snort/alert logfile? Has anyone of you ossec that take
a look to the snort logfiles running? Which log format I must enter in
the ossec.conf when I configure the position of the snort logfile?
Thanks in advance.
--
Andre Pawlowski
-------------------------------------------------------------------
Amerikas Verbündete müssen bei jedem neuen Präsidenten lernen, was für die
nächsten vier oder acht Jahre das Gute und das Böse ist - ein anstrengender
Prozess.
-Carl Friedrich von Weizsäcker