Hello, now it works.
Perhaps it has to do where in the include chain I insert the iplog_rules.xml in the ossec.conf. I changed the position from the last one to after syslog_rules.xml. Now I see an alert fired when a scan has taken place! Regards, onurbi
