Greetings: Given the following alert...
Dec 13 23:07:24 web2 suhosin[18198]: ALERT - script tried to increase memory_limit to 134217728 bytes which is above the allowed value (attacker '[IP ADDRESS OF ALLEGED ATTACKER]', file '[full path to file goes here]', line 65) ... if this rule was tied to an active response "as is" would ossec know to block the [IP ADDRESS OF ALLEGED ATTACKER]? If not, what modifications would I have to make? Thank you.
