|
Michael,
We view our OSSEC alerts is through a commercial Log Manager. The
syslog_output channel points to the Log Manager ...
<syslog_output>
<server>10.1.1.1</server> </syslog_output>
If multiple OSSEC servers were utilized, all pointing to the same Log Manager, you could view alerts from all of them their. Of course, this pushes the single point of failure to the LM. KenW
From: [email protected] [[email protected]] On Behalf Of Michael Altfield [[email protected]] Sent: Tuesday, August 04, 2009 5:28 PM To: ossec-list Subject: [ossec-list] Re: Agent alert queues to prevent data loss bump
On Wed, Jul 29, 2009 at 4:02 PM, Michael Altfield
<michael.sa@gmail.com> wrote:
|
- [ossec-list] Agent alert queues to prevent data loss Michael Altfield
- [ossec-list] Re: Agent alert queues to prevent data ... Ken Wachtler
- [ossec-list] Re: Agent alert queues to prevent d... Michael Altfield
- [ossec-list] Re: Agent alert queues to preve... Michael Altfield
- [ossec-list] Re: Agent alert queues to p... ddp
- [ossec-list] Re: Agent alert queues to p... Ken Wachtler
- [ossec-list] Re: Agent alert queues... Michael Altfield
- [ossec-list] Re: Agent alert qu... Ken Wachtler
- [ossec-list] Re: Agent alert qu... Michael Starks
- [ossec-list] Re: Agent alert queues to prevent data ... Daniel Cid
