On Tue, 6 Oct 2009 16:20:52 -0500, "Bristol, Gary L." <[email protected]>
wrote:
> I see comments on the web site about white listing a range of addresses,
> but I
> can't find in the Example configurations on where the entries would go.
Hello Gary,
Do you mean for Active Response? If so, just edit etc/ossec.conf and put
them in a global block, like so:
<global>
<white_list>1.2.3.0/24</white_list>
</global>
--
Michael Starks
[I] Immutable Security
http://www.immutablesecurity.com
Information Security, Privacy and Personal Liberty
Week of OSSEC - Every day a new OSSEC post - Oct 25-31
Speaking on "OSSEC in the Enterprise," Oct 29 2009
(http://www.immutablesecurity.com/index.php/2009/09/10/ossec-at-the-rochester-security-summit/)