Hi, I have OSSEC managing several hosts and the OSSEC alert log gets quickly very big. Is there any way to disable the logging of some events entirely apart from removing the rule that generates the log? I know I can set rules so that events do not generate email notifications but those events do still get logged.
Thank You, --MC
