Hi,
I am constantly getting the Rule: 18152 fired (level 10) -> "Multiple Windows Logon Failures." Sent to my inbox. It is being created and sent so many times because of a backup program. Is there a way to stop it being fired/emailed if the rule is triggered by a certain user ie/ the backup machines user? I have found a way to disable the rule from firing but would like to just avoid this one user. Fusspils -- Subscription settings: http://groups.google.com/group/ossec-list/subscribe?hl=en
