I am wondering if ossec parses F5 SSL Terminator/Reverse Proxy logs (app tier - Microsoft IIS and Apache servers) if they are fed as syslog messages.
Has any one ever tried it? Do I need to do any pre-processing before feeding it to ossec? Any pointers to accomplished this is greatly appreciated. Thanks, Ilango ---------------------------------------------------------------------- This message and any attachments are intended only for the use of the addressee and may contain information that is privileged and confidential. If the reader of the message is not the intended recipient or an authorized representative of the intended recipient, you are hereby notified that any dissemination of this communication is strictly prohibited. If you have received this communication in error, notify the sender immediately by return email and delete the message and any attachments from your system.
